Export limit exceeded: 15493 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395718 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 20799 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20799 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82527 | 1 Sciphi-ai | 1 R2r | 2026-09-04 | 7.5 High |
| R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint. Attackers can exploit the direct interpolation of filter keys into the SQL WHERE clause without parameterization or escaping to perform time-based and boolean-based data exfiltration from the application database. | ||||
| CVE-2026-82526 | 1 Sciphi-ai | 1 R2r | 2026-09-04 | 9.8 Critical |
| R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account. | ||||
| CVE-2026-82186 | 2026-09-04 | 4.1 Medium | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks. | ||||
| CVE-2024-7837 | 1 Firmanet | 1 Erp | 2026-09-04 | 8.2 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1. | ||||
| CVE-2026-81286 | 2 Wclovers, Wordpress | 2 Wcfm Marketplace, Wordpress | 2026-09-04 | 9.3 Critical |
| Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | ||||
| CVE-2026-85138 | 1 Seacms | 1 Seacms | 2026-09-03 | 7.3 High |
| A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | ||||
| CVE-2026-85388 | 1 Worklenz | 1 Worklenz | 2026-09-03 | 8.1 High |
| Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947. | ||||
| CVE-2026-84768 | 2 E4jvikwp, Wordpress | 2 Vikappointments Services Booking Calendar, Wordpress | 2026-09-03 | 9.3 Critical |
| Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | ||||
| CVE-2026-77790 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-03 | 5.5 Medium |
| The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | ||||
| CVE-2026-72775 | 1 N8n | 1 N8n | 2026-09-03 | 8.8 High |
| n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An authenticated user can inject arbitrary SQL executed against the connected PostgreSQL database with the configured credential's privileges, allowing full read and write access. | ||||
| CVE-2026-78080 | 1 Joodb.feenders.de | 1 Joodatabase Lite Extension For Joomla | 2026-09-03 | N/A |
| Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | ||||
| CVE-2026-76848 | 1 Typeorm | 1 Typeorm | 2026-09-03 | 7.5 High |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-85155 | 1 Wwbn | 1 Avideo | 2026-09-03 | 7.5 High |
| WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can exploit this ordering oracle to infer password hash values and recovery tokens, and trigger SQL errors that disclose the full query statement and database schema. | ||||
| CVE-2026-76176 | 1 Ocs Inventory Ng | 1 Ocsreports | 2026-09-03 | N/A |
| SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database. | ||||
| CVE-2026-76175 | 1 Ocs Inventory Ng | 1 Ocsreports | 2026-09-03 | N/A |
| SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be extracted from the database using SQL injection techniques. | ||||
| CVE-2026-9586 | 1 Sangoma | 2 Switchvox, Switchvox Smb Edition | 2026-09-03 | 9.8 Critical |
| An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. | ||||
| CVE-2026-82182 | 2 Wordpress, Wpvividplugins | 2 Wordpress, Wpvivid — Backup, Migration & Staging | 2026-09-02 | 4.1 Medium |
| The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks. | ||||
| CVE-2026-18765 | 1 Teracity | 1 E-osb | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. | ||||
| CVE-2026-18210 | 1 Trtek | 1 Products Store | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. | ||||
| CVE-2026-18630 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 8.8 High |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||