Total
20763 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-36937 | 2026-06-17 | N/A | 2.7 LOW | ||
| Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php. | |||||
| CVE-2026-36923 | 1 Oretnom23 | 1 Cab Management System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php. | |||||
| CVE-2026-36922 | 1 Oretnom23 | 1 Cab Management System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php. | |||||
| CVE-2026-36920 | 1 Janobe | 1 Online Reviewer System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php. | |||||
| CVE-2026-36919 | 1 Janobe | 1 Online Reviewer System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php. | |||||
| CVE-2026-36874 | 1 Razormist | 1 Basic Library System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php. | |||||
| CVE-2026-36873 | 1 Razormist | 1 Basic Library System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php. | |||||
| CVE-2026-36872 | 1 Razormist | 1 Basic Library System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php. | |||||
| CVE-2026-36670 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php. | |||||
| CVE-2026-36236 | 1 Janobe | 1 Engineers Online Portal | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. | |||||
| CVE-2026-36235 | 1 Itsourcecode | 1 Online Student Enrollment System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. | |||||
| CVE-2026-36234 | 1 Itsourcecode | 1 Online Student Enrollment System | 2026-06-17 | N/A | 9.8 CRITICAL |
| itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter. | |||||
| CVE-2026-36233 | 1 Itsourcecode | 1 Online Student Enrollment System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropriate cleaning or validation. | |||||
| CVE-2026-36232 | 1 Itsourcecode | 1 Online Student Enrollment System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation. | |||||
| CVE-2026-35614 | 1 Frappe | 1 Frappe | 2026-06-17 | N/A | 9.8 CRITICAL |
| Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fixed in 16.14.0 and 15.104.0. | |||||
| CVE-2026-35588 | 1 Nicolargo | 1 Glances | 2026-06-17 | N/A | 6.3 MEDIUM |
| Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix. | |||||
| CVE-2026-35228 | 2026-06-17 | N/A | 8.7 HIGH | ||
| Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool. Successful attacks of this vulnerability can result in Oracle MCP Server Helper Tool executing malicious SQL. | |||||
| CVE-2026-35168 | 1 Devcode | 1 Openstamanager | 2026-06-17 | N/A | 8.8 HIGH |
| OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via POST and executes them directly against the database without any validation, allowlist, or sanitization. An authenticated attacker with access to the Aggiornamenti module can execute arbitrary SQL statements including CREATE, DROP, ALTER, INSERT, UPDATE, DELETE, SELECT INTO OUTFILE, and any other SQL command supported by the MySQL server. Foreign key checks are explicitly disabled before execution (SET FOREIGN_KEY_CHECKS=0), further reducing database integrity protections. This issue has been patched in version 2.10.2. | |||||
| CVE-2026-34885 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34. | |||||
| CVE-2026-34747 | 1 Payloadcms | 1 Payload | 2026-06-17 | N/A | 8.5 HIGH |
| Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1. | |||||
