Export limit exceeded: 101670 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20971 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96827 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | ||||
| CVE-2026-96822 | 2026-09-30 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | ||||
| CVE-2026-96346 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-96345 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Estatik <= 4.3.5 versions. | ||||
| CVE-2026-94177 | 2026-09-30 | 8.5 High | ||
| Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. | ||||
| CVE-2026-94115 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | ||||
| CVE-2026-94082 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. | ||||
| CVE-2026-93621 | 2026-09-30 | 8.2 High | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | ||||
| CVE-2026-62085 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | ||||
| CVE-2026-103117 | 1 Os4ed | 1 Opensis-classic | 2026-09-30 | 4.7 Medium |
| A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-102912 | 1 Sourcecodester | 1 Online Leave Management System | 2026-09-30 | 4.7 Medium |
| A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | ||||
| CVE-2026-102909 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-09-30 | 7.3 High |
| A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | ||||
| CVE-2026-101110 | 1 Ordasoft.com | 1 Book Library (free) Extension For Joomla | 2026-09-30 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect. | ||||
| CVE-2026-101108 | 1 Ordasoft.com | 1 Vehicle Manager (free) Extension For Joomla | 2026-09-30 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect. | ||||
| CVE-2026-100752 | 1 Ordasoft.com | 1 Real Estate Manager (free) Extension For Joomla | 2026-09-30 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast. | ||||
| CVE-2026-18782 | 2026-09-30 | 9.8 Critical | ||
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | ||||
| CVE-2026-62097 | 2026-09-30 | 7.6 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27. | ||||
| CVE-2026-103116 | 1 Os4ed | 1 Opensis-classic | 2026-09-30 | 6.3 Medium |
| A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-97287 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Event Tickets <= 5.29.5 versions. | ||||
| CVE-2026-103115 | 1 Os4ed | 1 Opensis-classic | 2026-09-30 | 6.3 Medium |
| A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||