Vulnerabilities (CVE)

Filtered by CWE-89
Total 20763 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3046 1 Emiloi 1 E-logbook With Health Monitoring System For Covid-19 2026-06-17 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CVE-2026-3042 1 Admerc 1 Event Management System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVE-2026-3023 1 Wakyma 1 Wakyma 2026-06-17 N/A 8.8 HIGH
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting NoSQL commands, allowing them to list both pets and owner names.
CVE-2026-3022 1 Wakyma 1 Wakyma 2026-06-17 N/A 6.5 MEDIUM
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting special NoSQL commands, resulting in the attacker being able to obtain customer reports.
CVE-2026-3021 1 Wakyma 1 Wakyma 2026-06-17 N/A 6.5 MEDIUM
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/empleado'. This vulnerability could allow an authenticated user to alter a GET request to the affected endpoint for the purpose of injecting special NoSQL commands. This would lead to the enumeration of sensitive employee data.
CVE-2026-39946 1 Openbao 1 Openbao 2026-06-17 N/A 4.9 MEDIUM
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.
CVE-2026-39815 1 Fortinet 1 Fortiddos-f 2026-06-17 N/A 8.8 HIGH
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests
CVE-2026-39809 1 Fortinet 1 Forticlientems 2026-06-17 N/A 6.7 MEDIUM
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
CVE-2026-39581 2026-06-17 N/A 8.5 HIGH
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
CVE-2026-39574 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-39530 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
CVE-2026-39519 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
CVE-2026-39512 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
CVE-2026-39511 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
CVE-2026-39502 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
CVE-2026-39494 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.
CVE-2026-39493 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
CVE-2026-39492 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
CVE-2026-39441 2026-06-17 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
CVE-2026-39358 2026-06-17 N/A 7.2 HIGH
CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_admin, and sort_customer) of the Products and Logs endpoints in CubeCart v6.x. This allows an attacker to execute arbitrary SQL commands, compromising the confidentiality and integrity of the database. This vulnerability is fixed in 6.6.0.