Export limit exceeded: 20928 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20928 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102570 | 1 Clip-bucket | 1 Clipbucket | 2026-09-29 | 5.5 Medium |
| ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents. | ||||
| CVE-2023-54400 | 2026-09-29 | 9.8 Critical | ||
| Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18. | ||||
| CVE-2023-22491 | 1 Gatsbyjs | 1 Gatsby-transformer-remark | 2026-09-29 | 8.1 High |
| Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized. The vulnerability is present in gatsby-transformer-remark when passing input in data mode (querying MarkdownRemark nodes via GraphQL). Injected JavaScript executes in the context of the build server. To exploit this vulnerability untrusted/unsanitized input would need to be sourced by or added into a file processed by gatsby-transformer-remark. A patch has been introduced in `gatsby-transformer-remark@5.25.1` and `gatsby-transformer-remark@6.3.2` which mitigates the issue by disabling the `gray-matter` JavaScript Frontmatter engine. As a workaround, if an older version of `gatsby-transformer-remark` must be used, input passed into the plugin should be sanitized ahead of processing. It is encouraged for projects to upgrade to the latest major release branch for all Gatsby plugins to ensure the latest security updates and bug fixes are received in a timely manner. | ||||
| CVE-2015-20122 | 2026-09-29 | 7.5 High | ||
| Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17. | ||||
| CVE-2026-102491 | 1 Mahonelau | 1 Kykms | 2026-09-29 | 7.3 High |
| A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. The manipulation of the argument column leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-102569 | 1 Clip-bucket | 1 Clipbucket | 2026-09-29 | 5.5 Medium |
| ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to extract or modify database contents. | ||||
| CVE-2026-87963 | 1 Wordpress-extensions | 1 Yo | 2026-09-29 | 8.6 High |
| The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes. | ||||
| CVE-2026-66618 | 2 Flippercode, Wordpress-extensions | 2 Wp Maps, Wp Maps | 2026-09-29 | 7.6 High |
| Administrator SQL Injection in WP Maps <= 4.9.9 versions. | ||||
| CVE-2026-66619 | 2 Tribulant, Wordpress-extensions | 2 Newsletters, Newsletters | 2026-09-29 | 7.6 High |
| Administrator SQL Injection in Newsletters <= 4.18 versions. | ||||
| CVE-2026-66631 | 2 Moreconvert, Wordpress-extensions | 2 Woocommerce Wishlist, Mc Woocommerce Wishlist | 2026-09-29 | 7.6 High |
| Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | ||||
| CVE-2026-87767 | 1 Wordpress-extensions | 1 Wp Shortcut Link | 2026-09-29 | 8.6 High |
| The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | ||||
| CVE-2026-87770 | 1 Wordpress-extensions | 1 Price Drop Alert For Woo Commerce | 2026-09-29 | 8.6 High |
| The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | ||||
| CVE-2026-87771 | 1 Wordpress-extensions | 1 Product Question And Answer | 2026-09-29 | 8.6 High |
| The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | ||||
| CVE-2026-87774 | 1 Wordpress-extensions | 1 Tz Weekly Radio Schedule | 2026-09-29 | 8.6 High |
| The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | ||||
| CVE-2026-87775 | 1 Wordpress-extensions | 1 Tz Weekly Radio Schedule | 2026-09-29 | 8.6 High |
| The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | ||||
| CVE-2026-101108 | 1 Ordasoft.com | 1 Vehicle Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect. | ||||
| CVE-2026-100752 | 1 Ordasoft.com | 1 Real Estate Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast. | ||||
| CVE-2026-101110 | 1 Ordasoft.com | 1 Book Library (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect. | ||||
| CVE-2026-101091 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-29 | 7.1 High |
| SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication. | ||||
| CVE-2026-86843 | 2026-09-29 | N/A | ||
| The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy. | ||||