Total
20802 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-36525 | 2026-06-17 | N/A | 8.6 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection.This issue affects WPJobBoard: from n/a through 5.9.0. | |||||
| CVE-2023-36508 | 1 Bestwebsoft | 1 Contact Form To Db | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress contact-form-to-db allows SQL Injection.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.1. | |||||
| CVE-2023-36364 | 1 Monetdb | 1 Monetdb | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the rel_deps component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |||||
| CVE-2023-36363 | 1 Monetdb | 1 Monetdb | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the __nss_database_lookup component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |||||
| CVE-2023-36362 | 1 Monetdb | 1 Monetdb | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the rel_sequences component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |||||
| CVE-2023-36338 | 1 Inventory Management System Project | 1 Inventory Management System | 2026-06-17 | N/A | 5.3 MEDIUM |
| Inventory Management System 1 was discovered to contain a SQL injection vulnerability. | |||||
| CVE-2023-36311 | 1 Phpjabbers | 1 Document Creator | 2026-06-17 | N/A | 9.8 CRITICAL |
| There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | |||||
| CVE-2023-36293 | 1 Wmanager | 1 Wmanager | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in wmanager v.1.0.7 and before allows a remote attacker to obtain sensitive information via a crafted script to the company.php component. | |||||
| CVE-2023-36284 | 1 Webkul | 1 Qloapps | 2026-06-17 | N/A | 7.5 HIGH |
| An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database. | |||||
| CVE-2023-36263 | 1 Store-opart | 1 Op\'art Limit Quantity | 2026-06-17 | N/A | 9.8 CRITICAL |
| Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |||||
| CVE-2023-36213 | 1 Motocms | 1 Motocms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function. | |||||
| CVE-2023-36189 | 1 Langchain | 1 Langchain | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component. | |||||
| CVE-2023-36076 | 1 Pocketmanga | 1 Smanga | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php. | |||||
| CVE-2023-35924 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 8.6 HIGH |
| GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory. | |||||
| CVE-2023-35915 | 1 Automattic | 1 Woopayments | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0. | |||||
| CVE-2023-35911 | 1 Creative-solutions | 1 Contact Form Generator | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0. | |||||
| CVE-2023-35910 | 1 Quasar-form | 1 Quasar Form | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0. | |||||
| CVE-2023-35879 | 1 Woo | 1 Product Vendors | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.78. | |||||
| CVE-2023-35851 | 1 Sun.net | 1 Wmpro | 2026-06-17 | N/A | 7.5 HIGH |
| SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database. | |||||
| CVE-2023-35811 | 1 Sugarcrm | 1 Sugarcrm | 2026-06-17 | N/A | 8.8 HIGH |
| An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the REST API because of missing input validation. Regular user privileges can use used for exploitation. Editions other than Enterprise are also affected. | |||||
