Total
19885 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-15267 | 2026-07-28 | N/A | 6.5 MEDIUM | ||
| The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query — the value is re-read at line 144 using only sanitize_text_field() (overwriting the earlier absint() result), then concatenated into the SQL WHERE clause as an unquoted numeric operand using only esc_sql(), which does not protect against injection in that context, and finally string-interpolated into the $wpdb->prepare() format string, bypassing parameterization entirely. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
| CVE-2020-3973 | 2 Arista, Linux | 2 Velocloud Orchestrator, Linux Kernel | 2026-07-28 | 6.5 MEDIUM | 8.8 HIGH |
| The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged. | |||||
| CVE-2026-0603 | 2026-07-28 | N/A | 8.3 HIGH | ||
| A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service. | |||||
| CVE-2026-65877 | 2026-07-27 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | |||||
| CVE-2026-65876 | 2026-07-27 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | |||||
| CVE-2026-65766 | 2026-07-27 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | |||||
| CVE-2026-14189 | 2026-07-27 | N/A | 3.8 LOW | ||
| The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search. | |||||
| CVE-2026-59550 | 2026-07-27 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | |||||
| CVE-2026-59537 | 2026-07-27 | N/A | 7.6 HIGH | ||
| Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | |||||
| CVE-2026-63359 | 2026-07-27 | N/A | 9.8 CRITICAL | ||
| The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database. | |||||
| CVE-2026-17191 | 2026-07-27 | N/A | 9.1 CRITICAL | ||
| An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |||||
| CVE-2025-50455 | 2026-07-27 | N/A | 9.1 CRITICAL | ||
| SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE. | |||||
| CVE-2026-59549 | 2026-07-27 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | |||||
| CVE-2026-59538 | 2026-07-27 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | |||||
| CVE-2026-59527 | 2026-07-27 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | |||||
| CVE-2026-59551 | 2026-07-27 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | |||||
| CVE-2026-66427 | 2026-07-27 | N/A | 7.6 HIGH | ||
| Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | |||||
| CVE-2026-59533 | 2026-07-27 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | |||||
| CVE-2026-57308 | 1 Apache | 1 Syncope | 2026-07-27 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue. | |||||
| CVE-2026-60582 | 2026-07-27 | N/A | 8.3 HIGH | ||
| Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H). | |||||
