Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.8
CVE-2026-72775
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifi…
No fix yet
MEDIUM 5.3
CVE-2026-72750
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates ex…
No fix yet
HIGH 7.1
CVE-2026-72609
An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_re…
No fix yet
HIGH 7.1
CVE-2026-72607
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_ba…
No fix yet
MEDIUM 6.5
CVE-2026-72608
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_cr…
No fix yet
HIGH 8.8
CVE-2026-72562
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via…
No fix yet
CRITICAL 9.8
CVE-2026-72599
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. Th…
No fix yet
HIGH 8.8
CVE-2026-72558
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE cla…
No fix yet
CRITICAL 9.8
CVE-2026-72550
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statement…
No fix yet
CRITICAL 9.8
CVE-2026-19425
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…
No fix yet
MEDIUM 6.3
CVE-2026-66770
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag…
No fix yet
MEDIUM 6.5
CVE-2026-72908
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts…
No fix yet
CRITICAL 9.3
CVE-2025-13294
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke…
No fix yet
CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …
Metabase
0.58.24 / 0.59.21+
CRITICAL 10.0
CVE-2026-72899
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p…
No fix yet
HIGH 7.1
CVE-2026-72731
Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a…
No fix yet
CRITICAL 9.8
CVE-2026-63106
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr…
No fix yet
CRITICAL 9.8
CVE-2026-72565
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read ar…
No fix yet
CRITICAL 9.8
CVE-2026-32227
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the…
Ranger
No fix yet
CRITICAL 9.1
CVE-2026-19053
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unau…
No fix yet
HIGH 8.6
CVE-2026-19049
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on…
No fix yet
MEDIUM 5.8
CVE-2026-16949
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthent…
No fix yet
HIGH 7.3
CVE-2026-19384
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admi…
No fix yet
MEDIUM 6.3
CVE-2026-19364
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorcon…
No fix yet
HIGH 7.3
CVE-2026-19355
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/lis…
No fix yet
MEDIUM 6.3
CVE-2026-19354
A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file c…
No fix yet
HIGH 7.3
CVE-2026-19351
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/Sel…
No fix yet
MEDIUM 6.3
CVE-2026-19347
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php…
No fix yet
HIGH 7.3
CVE-2026-19344
A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/co…
No fix yet
HIGH 7.3
CVE-2026-19343
A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Admi…
No fix yet