Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.9
CVE-2026-50747
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi …
Unifi Talk Application
5.2.2+
HIGH 8.5
CVE-2026-57765
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
Mitigation only
HIGH 8.5
CVE-2026-57752
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
No fix yet
HIGH 8.5
CVE-2026-57756
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-57683
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
Mitigation only
HIGH 8.5
CVE-2026-57687
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-57679
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
No fix yet
HIGH 8.5
CVE-2025-69094
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-14029
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in…
Mitigation only
HIGH 7.5
CVE-2026-8441
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action i…
Mitigation only
CRITICAL 9.8
CVE-2026-52186
SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc c…
Mitigation only
CRITICAL 9.8
CVE-2026-14363
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…
Cargo
3.9.1+
CRITICAL 9.8
CVE-2026-58521
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…
Cargo
3.9.1+
MEDIUM 6.5
CVE-2026-51946
SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive in…
Mitigation only
CRITICAL 9.8
CVE-2026-34101
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extensio…
Mitigation only
CRITICAL 9.8
CVE-2026-34102
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where i…
Mitigation only
CRITICAL 9.8
CVE-2026-34103
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extensio…
Mitigation only
CRITICAL 9.8
CVE-2026-34104
Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE…
Mitigation only
CRITICAL 9.8
CVE-2026-34105
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, ext…
Mitigation only
CRITICAL 9.8
CVE-2026-34099
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = …
Mitigation only
CRITICAL 9.8
CVE-2026-34100
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, t…
Mitigation only
CRITICAL 9.8
CVE-2026-57517
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQ…
Mitigation only
MEDIUM 6.5
CVE-2026-13454
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and includ…
Mitigation only
HIGH 7.5
CVE-2026-11823
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign…
Mitigation only
MEDIUM 6.5
CVE-2026-12110
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'ta…
Mitigation only
MEDIUM 6.5
CVE-2026-12090
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wp…
Mitigation only
CRITICAL 9.3
CVE-2026-55721
Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie valu…
Mitigation only
MEDIUM 5.5
CVE-2026-3602
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is v…
App Connect Enterprise
12.0.12.27 / 13.0.8.0+
HIGH 7.6
CVE-2026-58376
Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary …
Patch available
MEDIUM 5.4
CVE-2025-53648
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
Users are recommended to…
Gravitino
1.0.0+