Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-39196
Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition f…
Mitigation only
HIGH 8.8
CVE-2026-36670
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows a…
Mitigation only
HIGH 7.1
CVE-2019-25746
WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database quer…
No fix yet
HIGH 8.2
CVE-2016-20071
The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to …
No fix yet
HIGH 8.2
CVE-2016-20072
BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL que…
No fix yet
HIGH 8.2
CVE-2016-20073
Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu…
No fix yet
HIGH 8.2
CVE-2016-20068
WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to …
No fix yet
HIGH 8.2
CVE-2016-20069
WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to …
No fix yet
MEDIUM 6.3
CVE-2026-12206
A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/…
Mitigation only
MEDIUM 6.3
CVE-2026-12188
A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/c…
Mitigation only
HIGH 7.6
CVE-2026-6428
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x befor…
Mitigation only
HIGH 7.5
CVE-2026-9848
The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.…
Mitigation only
MEDIUM 6.3
CVE-2026-12131
A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \applic…
Mitigation only
CRITICAL 9.1
CVE-2026-44172
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, …
MariaDB
Mitigation only
MEDIUM 6.9
CVE-2026-41581
Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This i…
Mitigation only
MEDIUM 5.9
CVE-2026-48613
SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing …
Mitigation only
CRITICAL 9.8
CVE-2026-45060
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind…
Mitigation only
HIGH 8.8
CVE-2026-45418
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple …
Mitigation only
CRITICAL 9.3
CVE-2026-39494
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind …
Mitigation only
CRITICAL 9.3
CVE-2026-42647
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection.
…
Mitigation only
HIGH 7.5
CVE-2026-11945
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code…
Postgresql Anonymizer
3.1.1+
CRITICAL 9.8
CVE-2026-38581
SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFor…
Mitigation only
MEDIUM 6.5
CVE-2026-53474
A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xls…
Migration Assessment
0.13.5+
HIGH 8.8
CVE-2026-52758
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries withou…
Ghidra
12.1+
HIGH 8.8
CVE-2026-49498
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double…
Ghidra
12.1+
HIGH 7.5
CVE-2026-3018
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and inclu…
Mitigation only
HIGH 8.6
CVE-2026-3326
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action avail…
Mitigation only
HIGH 8.8
CVE-2026-50636
The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), w…
Patch available
CRITICAL 9.8
CVE-2026-8025
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform…
Mitigation only
CRITICAL 9.8
CVE-2026-7486
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injectio…
Mitigation only