Export limit exceeded: 21105 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21105 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96601 | 1 Abdurrab5 | 1 Online-makeup-store | 2026-09-24 | 7.3 High |
| A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure. | ||||
| CVE-2026-77874 | 1 Ibm | 1 Enterprise Build Of Quarkus | 2026-09-24 | 8.6 High |
| IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-96751 | 1 Pmticket | 1 Project-management-software | 2026-09-24 | 7.3 High |
| A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-94144 | 1 Drogon | 1 Drogon | 2026-09-24 | 7.3 High |
| A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-82011 | 3 Adobe, Linux, Microsoft | 4 Campaign, Campaign Classic, Linux Kernel and 1 more | 2026-09-24 | 9.1 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-96803 | 1 Java110 | 1 Microcommunity | 2026-09-24 | 7.3 High |
| A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78311 | 1 Deltaww | 1 Diaenergie | 2026-09-24 | 8.8 High |
| SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | ||||
| CVE-2026-78309 | 1 Deltaww | 1 Diaenergie | 2026-09-24 | 8.8 High |
| SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | ||||
| CVE-2026-93972 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-09-24 | 7.3 High |
| A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-96826 | 2 Shazzad Hossain Khan, Wordpress | 2 W4 Post List, Wordpress | 2026-09-24 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This issue affects W4 Post List: from n/a through 3.0.6. | ||||
| CVE-2026-96600 | 1 Isotope | 1 Isotope-core | 2026-09-24 | 5.5 Medium |
| Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table. | ||||
| CVE-2026-94174 | 2 Webfactory, Wordpress | 2 Email Log, Wordpress | 2026-09-24 | 7.6 High |
| Administrator SQL Injection in Email Log <= 2.63 versions. | ||||
| CVE-2026-95593 | 2 Ben Roberts, Wordpress | 2 Ultimeter, Wordpress | 2026-09-24 | 7.6 High |
| Editor SQL Injection in Ultimeter <= 3.0.8 versions. | ||||
| CVE-2026-93527 | 2 Bdthemes, Wordpress | 2 Live Copy Paste For Elementor, Wordpress | 2026-09-23 | 8.5 High |
| Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. | ||||
| CVE-2026-95522 | 2 Syed Balkhi, Wordpress | 2 Easy Digital Downloads, Wordpress | 2026-09-23 | 7.6 High |
| Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | ||||
| CVE-2026-95590 | 2 Tainacan, Wordpress | 2 Tainacan, Wordpress | 2026-09-23 | 7.1 High |
| Subscriber SQL Injection in Tainacan <= 1.2.0 versions. | ||||
| CVE-2026-82010 | 3 Adobe, Linux, Microsoft | 4 Campaign, Campaign Classic, Linux Kernel and 1 more | 2026-09-23 | 9.9 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-96514 | 1 Neethuharii | 1 Cafemanagement | 2026-09-23 | 7.3 High |
| A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-92692 | 1 Sulu | 1 Sulu | 2026-09-23 | N/A |
| Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8. | ||||
| CVE-2026-94124 | 2 Levelfourdevelopment, Wordpress | 2 Wp-easycart, Wordpress | 2026-09-23 | 8.5 High |
| Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. | ||||