Total
20012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-49076 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. | |||||
| CVE-2026-48967 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. | |||||
| CVE-2026-22332 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. | |||||
| CVE-2025-59554 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | |||||
| CVE-2026-28576 | 1 Google | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2025-57819 | 1 Sangoma | 1 Freepbx | 2026-06-17 | N/A | 9.8 CRITICAL |
| FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3. | |||||
| CVE-2026-54819 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0. | |||||
| CVE-2026-54815 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6. | |||||
| CVE-2026-54813 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0. | |||||
| CVE-2026-54811 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. | |||||
| CVE-2026-54808 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4. | |||||
| CVE-2026-54187 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | |||||
| CVE-2026-22335 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. | |||||
| CVE-2025-69135 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. | |||||
| CVE-2026-22340 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. | |||||
| CVE-2026-49080 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. | |||||
| CVE-2026-49079 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. | |||||
| CVE-2026-39596 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | |||||
| CVE-2026-39438 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. | |||||
| CVE-2026-54186 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. | |||||
