Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2025-67403
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
No fix yet
CRITICAL 9.8
CVE-2025-67404
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla…
No fix yet
HIGH 7.3
CVE-2025-67405
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
No fix yet
HIGH 7.3
CVE-2025-67406
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). T…
No fix yet
HIGH 7.3
CVE-2025-67407
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
No fix yet
HIGH 7.3
CVE-2025-67408
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
No fix yet
CRITICAL 9.8
CVE-2025-69942
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
No fix yet
CRITICAL 9.8
CVE-2025-69943
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
Mitigation only
HIGH 7.3
CVE-2025-69944
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.
No fix yet
CRITICAL 9.8
CVE-2025-65340
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
No fix yet
HIGH 8.8
CVE-2026-5490
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio…
No fix yet
HIGH 8.7
CVE-2026-8339
A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authentica…
No fix yet
CRITICAL 9.1
CVE-2026-51992
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries …
Mitigation only
CRITICAL 9.8
CVE-2026-65890
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…
Gridbox
2.20.2+
MEDIUM 5.1
CVE-2026-33385
A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip…
No fix yet
HIGH 7.1
CVE-2026-12895
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interp…
No fix yet
CRITICAL 9.1
CVE-2026-63229
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO …
Mitigation only
CRITICAL 9.1
CVE-2026-63230
A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, …
No fix yet
HIGH 8.1
CVE-2026-63231
A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-f…
No fix yet
CRITICAL 9.9
CVE-2026-63232
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
reinforcem…
No fix yet
CRITICAL 9.9
CVE-2026-63233
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall an…
Mitigation only
CRITICAL 9.9
CVE-2026-63234
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark
assessmen…
No fix yet
CRITICAL 9.8
CVE-2026-54658
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl…
No fix yet
CRITICAL 9.4
CVE-2026-6881
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive …
Mitigation only
MEDIUM 6.3
CVE-2026-11391
Tanium addressed a SQL injection vulnerability in Patch.
No fix yet
HIGH 8.1
CVE-2026-7769
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0…
Sterling B2b Integrator
after 6.2.2.0_1
CRITICAL 9.0
CVE-2026-50736
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads…
No fix yet
MEDIUM 6.5
CVE-2026-15304
The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4.…
No fix yet
HIGH 7.5
CVE-2026-14785
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1…
No fix yet
CRITICAL 9.8
CVE-2026-16462
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL comm…
No fix yet