Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-11024
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. …
Mitigation only
MEDIUM 6.5
CVE-2026-6225
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection vi…
Mitigation only
HIGH 7.1
CVE-2026-46445
SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
Patch available
HIGH 7.1
CVE-2026-46446
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@…
Patch available
MEDIUM 6.5
CVE-2026-5486
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addon…
Mitigation only
HIGH 8.1
CVE-2026-29206
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging …
Mitigation only
HIGH 7.5
CVE-2026-44446
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection t…
Erpnext
15.104.3 / 16.14.0+
HIGH 7.5
CVE-2026-44447
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through special…
Erpnext
16.9.0+
MEDIUM 5.3
CVE-2026-44381
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-contr…
Misp
2.5.37+
HIGH 8.7
CVE-2026-44418
EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view pass…
Patch available
HIGH 7.2
CVE-2026-39358
CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorti…
Mitigation only
HIGH 8.8
CVE-2026-42550
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL stateme…
Mitigation only
CRITICAL 9.8
CVE-2026-42031
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor…
Ckan
2.10.10 / 2.11.5+
MEDIUM 6.1
CVE-2026-0242
A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product d…
Mitigation only
HIGH 7.1
CVE-2020-37226
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by inje…
No fix yet
HIGH 8.2
CVE-2020-37218
Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQ…
No fix yet
HIGH 7.1
CVE-2020-37224
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by inje…
No fix yet
MEDIUM 6.5
CVE-2026-4608
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all vers…
Mitigation only
MEDIUM 6.5
CVE-2026-37429
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vuln…
Mitigation only
MEDIUM 6.5
CVE-2026-37428
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vuln…
Mitigation only
HIGH 7.5
CVE-2026-4798
The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and includi…
Mitigation only
HIGH 7.5
CVE-2026-6929
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sort…
Mitigation only
MEDIUM 6.5
CVE-2026-7619
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Inject…
Mitigation only
HIGH 7.2
CVE-2026-6888
Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to
execute arbitrary commands via a specific i…
Mitigation only
HIGH 7.5
CVE-2026-1250
The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all v…
Mitigation only
HIGH 7.2
CVE-2026-44864
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.2
CVE-2026-44860
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.2
CVE-2026-44861
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.2
CVE-2026-44862
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.2
CVE-2026-44863
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…
Arubaos
8.10.0.22 / 8.12.0.7+