Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-38733 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | |||||
| CVE-2021-38732 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | |||||
| CVE-2021-38731 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. | |||||
| CVE-2021-38730 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | |||||
| CVE-2021-38729 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. | |||||
| CVE-2021-38727 | 1 Thedaylightstudio | 1 Fuel Cms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items | |||||
| CVE-2021-38723 | 1 Thedaylightstudio | 1 Fuel Cms | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items | |||||
| CVE-2021-38706 | 1 Cliniccases | 1 Cliniccases | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter. | |||||
| CVE-2021-38694 | 1 Softvibe | 1 Saraban | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection. | |||||
| CVE-2021-38574 | 1 Foxitsoftware | 2 Foxit Reader, Phantompdf | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string. | |||||
| CVE-2021-38481 | 1 Auvesy | 1 Versiondog | 2026-06-17 | 7.5 HIGH | 8.1 HIGH |
| The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker may send a malicious payload that can enable the user to execute another SQL expression by sending a specific string. | |||||
| CVE-2021-38393 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | 10.0 HIGH | 9.8 CRITICAL |
| A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER. | |||||
| CVE-2021-38391 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | 10.0 HIGH | 9.8 CRITICAL |
| A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER. | |||||
| CVE-2021-38390 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | 10.0 HIGH | 9.8 CRITICAL |
| A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER. | |||||
| CVE-2021-38324 | 1 Smartypantsplugins | 1 Sp Rental Manager | 2026-06-17 | 5.0 MEDIUM | 8.2 HIGH |
| The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3. | |||||
| CVE-2021-38303 | 1 Surelinesystems | 1 Sureedge Migrator | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360. | |||||
| CVE-2021-38302 | 1 Newsletter Project | 1 Newsletter | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection. | |||||
| CVE-2021-38239 | 1 Dataease | 1 Dataease | 2026-06-17 | N/A | 7.5 HIGH |
| SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10. | |||||
| CVE-2021-38217 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. | |||||
| CVE-2021-38176 | 1 Sap | 4 Landscape Transformation, Landscape Transformation Replication Server, S\/4hana and 1 more | 2026-06-17 | 9.0 HIGH | 8.8 HIGH |
| Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system. | |||||
