Total
20691 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66594 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | |||||
| CVE-2026-61518 | 2026-08-20 | N/A | 8.8 HIGH | ||
| ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote API user holding any single low-privilege function permission can inject arbitrary SQL to delete or modify records across all tenants in the control panel database and extract arbitrary data via blind boolean inference, including password hashes and client records. | |||||
| CVE-2026-73998 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | |||||
| CVE-2026-66592 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | |||||
| CVE-2026-20327 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. | |||||
| CVE-2026-20030 | 2026-08-20 | N/A | 10.0 CRITICAL | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89. | |||||
| CVE-2026-32552 | 2026-08-20 | N/A | 8.5 HIGH | ||
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | |||||
| CVE-2026-73183 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | |||||
| CVE-2026-73391 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | |||||
| CVE-2026-19926 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded. | |||||
| CVE-2026-76050 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |||||
| CVE-2026-75080 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2026-73388 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | |||||
| CVE-2026-75876 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-73339 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | |||||
| CVE-2026-74015 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | |||||
| CVE-2026-75088 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument delid can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2026-73365 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | |||||
| CVE-2026-66622 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | |||||
| CVE-2026-19934 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. | |||||
