Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-44204
Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /ass…
Patch available
HIGH 8.8
CVE-2026-25088
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, Forti…
Fortindr
7.4.10 / 7.6.3+
HIGH 7.2
CVE-2025-53681
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7…
Fortimail
7.2.9 / 7.4.6+
CRITICAL 9.8
CVE-2026-34187
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affec…
Pandora Fms
777.17 / 802+
HIGH 8.8
CVE-2026-8111
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exe…
Endpoint Manager
after 2022
HIGH 8.8
CVE-2026-43937
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttri…
Mitigation only
HIGH 7.8
CVE-2026-32687
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifica…
Postgrex
0.22.0+
CRITICAL 9.1
CVE-2026-27851
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe…
Dovecot
2.4.4 / 3.1.5+
HIGH 7.7
CVE-2026-45218
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL …
Mitigation only
HIGH 8.5
CVE-2026-42741
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Ed…
Mitigation only
HIGH 8.5
CVE-2026-42742
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite a…
Mitigation only
HIGH 8.5
CVE-2026-45211
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce wo…
Mitigation only
HIGH 7.6
CVE-2026-45213
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQ…
Mitigation only
HIGH 8.5
CVE-2026-45214
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addon…
Mitigation only
MEDIUM 6.0
CVE-2026-41125
A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions…
Mitigation only
CRITICAL 9.8
CVE-2025-6577
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. …
Mitigation only
MEDIUM 6.5
CVE-2026-5028
The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-artic…
No fix yet
HIGH 7.5
CVE-2026-2993
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insu…
Mitigation only
CRITICAL 9.6
CVE-2026-34260
SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL sta…
Mitigation only
HIGH 7.3
CVE-2026-36962
SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative …
Mitigation only
CRITICAL 9.8
CVE-2026-38567
HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries witho…
Mitigation only
HIGH 8.8
CVE-2026-7815
SQL injection vulnerability in pgAdmin 4 Maintenance Tool.
Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup…
Pgadmin 4
9.15+
MEDIUM 6.0
CVE-2026-6093
Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issu…
Mitigation only
HIGH 8.2
CVE-2021-47941
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries…
No fix yet
HIGH 8.2
CVE-2021-47930
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attacker…
No fix yet
HIGH 8.2
CVE-2021-47928
Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by …
No fix yet
MEDIUM 6.3
CVE-2026-8231
A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The m…
Mitigation only
CRITICAL 9.8
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL…
PHP
8.2.31 / 8.3.31+
HIGH 7.0
CVE-2026-8207
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/Gib…
Mitigation only
CRITICAL 10.0
CVE-2026-42287
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attack…
Mitigation only