Vulnerabilities (CVE)

Filtered by CWE-89
Total 20129 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3057 1 A54552239 1 Pearprojectapi 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-3046 1 Emiloi 1 E-logbook With Health Monitoring System For Covid-19 2026-06-17 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CVE-2026-3042 1 Admerc 1 Event Management System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVE-2026-3023 1 Wakyma 1 Wakyma 2026-06-17 N/A 8.8 HIGH
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting NoSQL commands, allowing them to list both pets and owner names.
CVE-2026-3022 1 Wakyma 1 Wakyma 2026-06-17 N/A 6.5 MEDIUM
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting special NoSQL commands, resulting in the attacker being able to obtain customer reports.
CVE-2026-3021 1 Wakyma 1 Wakyma 2026-06-17 N/A 6.5 MEDIUM
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/empleado'. This vulnerability could allow an authenticated user to alter a GET request to the affected endpoint for the purpose of injecting special NoSQL commands. This would lead to the enumeration of sensitive employee data.
CVE-2026-39946 1 Openbao 1 Openbao 2026-06-17 N/A 4.9 MEDIUM
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.
CVE-2026-39815 1 Fortinet 1 Fortiddos-f 2026-06-17 N/A 8.8 HIGH
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests
CVE-2026-39809 1 Fortinet 1 Forticlientems 2026-06-17 N/A 6.7 MEDIUM
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
CVE-2026-39581 2026-06-17 N/A 8.5 HIGH
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
CVE-2026-39574 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-39530 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
CVE-2026-39519 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
CVE-2026-39512 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
CVE-2026-39511 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
CVE-2026-39502 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
CVE-2026-39494 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.
CVE-2026-39493 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
CVE-2026-39492 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
CVE-2026-39441 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.