Total
20706 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-69937 | 2026-07-31 | N/A | 9.8 CRITICAL | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. | |||||
| CVE-2025-69938 | 2026-07-31 | N/A | 9.8 CRITICAL | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | |||||
| CVE-2026-22620 | 2026-07-31 | N/A | 8.6 HIGH | ||
| Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. | |||||
| CVE-2026-5490 | 2026-07-31 | N/A | 8.8 HIGH | ||
| DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. . Was ZDI-CAN-28726. | |||||
| CVE-2025-50455 | 2026-07-30 | N/A | 9.1 CRITICAL | ||
| SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE. | |||||
| CVE-2026-15153 | 2026-07-30 | N/A | 6.8 MEDIUM | ||
| The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks. | |||||
| CVE-2026-13395 | 2026-07-30 | N/A | 8.6 HIGH | ||
| The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database. | |||||
| CVE-2025-69942 | 2026-07-30 | N/A | 9.8 CRITICAL | ||
| kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. | |||||
| CVE-2025-65340 | 2026-07-30 | N/A | 9.8 CRITICAL | ||
| kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. | |||||
| CVE-2026-15929 | 2026-07-30 | N/A | N/A | ||
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions. | |||||
| CVE-2026-17191 | 2026-07-30 | N/A | 9.1 CRITICAL | ||
| An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |||||
| CVE-2026-33385 | 2026-07-30 | N/A | N/A | ||
| A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification capabilities. The SQL injection vulnerability primarily enables bypassing front-end validation controls and potential database destruction. Given the trust model in which this application is designed to be administered, remediation of this issue was not deemed necessary by the vendor. This vulnerability has been found in version 6.8, but other versions might also be vulnerable. | |||||
| CVE-2026-8339 | 2026-07-30 | N/A | N/A | ||
| A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands. | |||||
| CVE-2026-11391 | 2026-07-30 | N/A | 6.3 MEDIUM | ||
| Tanium addressed a SQL injection vulnerability in Patch. | |||||
| CVE-2026-4978 | 2026-07-30 | N/A | 9.8 CRITICAL | ||
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34. | |||||
| CVE-2026-63233 | 2026-07-30 | N/A | 9.9 CRITICAL | ||
| A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | |||||
| CVE-2026-63231 | 2026-07-30 | N/A | 8.1 HIGH | ||
| A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover. | |||||
| CVE-2026-63234 | 2026-07-30 | N/A | 9.9 CRITICAL | ||
| A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | |||||
| CVE-2026-63230 | 2026-07-30 | N/A | 9.1 CRITICAL | ||
| A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint. | |||||
| CVE-2026-63229 | 2026-07-30 | N/A | 9.1 CRITICAL | ||
| A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover. | |||||
