Export limit exceeded: 10826 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 21014 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21014 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101018 | 2 Dayrui, Xunruicms | 2 Xunruicms, Xunruicms | 2026-10-01 | 4.7 Medium |
| A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-102578 | 1 Moodle | 1 Moodle | 2026-10-01 | 5.5 Medium |
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. | ||||
| CVE-2026-103338 | 2026-10-01 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-103248 | 1 N8n | 1 N8n | 2026-10-01 | 9 Critical |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request. | ||||
| CVE-2026-102109 | 1 Kiteworks | 1 Secure Data Forms | 2026-10-01 | 7.1 High |
| A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use. | ||||
| CVE-2026-102098 | 1 Kiteworks | 1 Core | 2026-10-01 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function. | ||||
| CVE-2026-101012 | 1 Mathurvishal | 1 Cloudclassroom-php-project | 2026-10-01 | 7.3 High |
| A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-100894 | 1 Mathurvishal | 1 Cloudclassroom-php-project | 2026-10-01 | 6.3 Medium |
| A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-79536 | 2026-10-01 | 9.1 Critical | ||
| bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement. | ||||
| CVE-2026-96428 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | ||||
| CVE-2026-96429 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
| CVE-2026-86843 | 1 Apache | 1 Airflow Teradata Provider | 2026-09-30 | 6.3 Medium |
| The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy. | ||||
| CVE-2015-20122 | 1 Yonyou | 1 A6 Oa | 2026-09-30 | 7.5 High |
| Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17. | ||||
| CVE-2023-54400 | 1 Fumasoft | 1 Fumeng Cloud | 2026-09-30 | 9.8 Critical |
| Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18. | ||||
| CVE-2026-72510 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. | ||||
| CVE-2026-63713 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-68954 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. | ||||
| CVE-2026-68068 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-72507 | 1 Toptech Systems | 2 Tms7, Tophat | 2026-09-30 | 9 Critical |
| The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. | ||||
| CVE-2026-82307 | 1 Dolusoft Software Technologies | 1 Soplog | 2026-09-30 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1. | ||||