Export limit exceeded: 20979 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20979 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103253 | 1 N8n | 1 N8n | 2026-10-01 | 8.7 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges. | ||||
| CVE-2026-103248 | 1 N8n | 1 N8n | 2026-10-01 | 9 Critical |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request. | ||||
| CVE-2026-75786 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards. | ||||
| CVE-2026-81809 | 2026-10-01 | N/A | ||
| The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-89296 | 2026-10-01 | N/A | ||
| The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-103543 | 1 Itsourcecode | 1 Leave Management System | 2026-10-01 | 6.3 Medium |
| A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of the argument LEAVTID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-102098 | 1 Kiteworks | 1 Core | 2026-10-01 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function. | ||||
| CVE-2026-102109 | 1 Kiteworks | 1 Secure Data Forms | 2026-10-01 | 7.1 High |
| A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use. | ||||
| CVE-2026-79536 | 2026-10-01 | 9.1 Critical | ||
| bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement. | ||||
| CVE-2026-96428 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | ||||
| CVE-2026-96429 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
| CVE-2026-86843 | 1 Apache | 1 Airflow Teradata Provider | 2026-09-30 | 6.3 Medium |
| The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy. | ||||
| CVE-2015-20122 | 1 Yonyou | 1 A6 Oa | 2026-09-30 | 7.5 High |
| Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17. | ||||
| CVE-2023-54400 | 1 Fumasoft | 1 Fumeng Cloud | 2026-09-30 | 9.8 Critical |
| Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18. | ||||
| CVE-2026-72510 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. | ||||
| CVE-2026-63713 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-68954 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. | ||||
| CVE-2026-68068 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-72507 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-82307 | 1 Dolusoft Software Technologies | 1 Soplog | 2026-09-30 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1. | ||||