Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2026-28168
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
No fix yet
HIGH 8.5
CVE-2026-28156
Subscriber SQL Injection in Do Lasso <= 358 versions.
No fix yet
CRITICAL 9.3
CVE-2026-28001
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
No fix yet
HIGH 8.5
CVE-2026-28002
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection.
…
No fix yet
CRITICAL 9.3
CVE-2026-28142
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
No fix yet
HIGH 7.5
CVE-2026-27538
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
No fix yet
HIGH 8.8
CVE-2026-15741
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attack…
No fix yet
HIGH 8.8
CVE-2026-11840
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL inj…
No fix yet
HIGH 7.1
CVE-2026-73331
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges …
No fix yet
HIGH 8.7
CVE-2026-73332
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers t…
No fix yet
HIGH 8.0
CVE-2026-72807
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks funct…
No fix yet
HIGH 7.4
CVE-2026-67579
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged …
Ash Framework
No fix yet
CRITICAL 9.8
CVE-2026-17111
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…
I
No fix yet
CRITICAL 9.6
CVE-2026-73300
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru…
No fix yet
HIGH 8.8
CVE-2026-44741
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's …
No fix yet
HIGH 7.8
CVE-2026-17418
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elemen…
I
after 7.6
MEDIUM 6.5
CVE-2026-17419
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used…
I
after 7.6
CRITICAL 9.3
CVE-2026-66659
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject…
No fix yet
HIGH 8.6
CVE-2026-18474
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL inje…
No fix yet
HIGH 8.1
CVE-2026-18230
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its aut…
No fix yet
HIGH 8.1
CVE-2026-18057
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing u…
No fix yet
HIGH 8.1
CVE-2026-16977
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQ…
No fix yet
HIGH 8.8
CVE-2026-13613
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing…
No fix yet
CRITICAL 9.8
CVE-2026-73211
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac…
No fix yet
CRITICAL 9.0
CVE-2026-48381
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…
No fix yet
HIGH 7.5
CVE-2016-20097
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to …
No fix yet
HIGH 7.5
CVE-2022-50997
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated rem…
No fix yet
HIGH 7.8
CVE-2026-65673
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to…
Entra Connect
No fix yet
CRITICAL 9.1
CVE-2026-73069
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MOD…
No fix yet
CRITICAL 9.8
CVE-2026-46670
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat…
No fix yet