Export limit exceeded: 20971 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20971 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82538 | 1 Ilias | 1 Ilias | 2026-09-30 | 8.8 High |
| ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover. | ||||
| CVE-2026-103229 | 1 Adithyayelloju | 1 Restaurant-management-system | 2026-09-30 | 7.3 High |
| A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-68068 | 2026-09-30 | 9 Critical | ||
| The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-72507 | 2026-09-30 | 9 Critical | ||
| The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-68954 | 2026-09-30 | 9 Critical | ||
| The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. | ||||
| CVE-2026-63713 | 2026-09-30 | 9 Critical | ||
| The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-72510 | 2026-09-30 | 9 Critical | ||
| The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. | ||||
| CVE-2026-102456 | 1 Digiwin | 1 Easyflow .net | 2026-09-30 | 6.5 Medium |
| EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents. | ||||
| CVE-2026-6806 | 2026-09-30 | 7.5 High | ||
| The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-16596 | 2026-09-30 | 6.5 Medium | ||
| The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-100847 | 1 Azuracast | 1 Azuracast | 2026-09-30 | 7.5 High |
| AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings. | ||||
| CVE-2023-54400 | 2026-09-30 | 9.8 Critical | ||
| Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18. | ||||
| CVE-2026-103232 | 1 Adithyayelloju | 1 Restaurant-management-system | 2026-09-30 | 7.3 High |
| A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-103231 | 1 Adithyayelloju | 1 Restaurant-management-system | 2026-09-30 | 7.3 High |
| A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-103230 | 1 Adithyayelloju | 1 Restaurant-management-system | 2026-09-30 | 7.3 High |
| A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-82307 | 2026-09-30 | 9.8 Critical | ||
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1. | ||||
| CVE-2026-102578 | 1 Moodle | 1 Moodle | 2026-09-30 | 5.5 Medium |
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. | ||||
| CVE-2026-76570 | 2026-09-30 | N/A | ||
| Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries. | ||||
| CVE-2026-97293 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions. | ||||
| CVE-2026-96828 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | ||||