Search Results (21105 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-79794 1 Hewlett Packard Enterprise (hpe) 1 Clearpass Policy Manager (cppm) 2026-10-07 9.1 Critical
A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
CVE-2026-105186 1 Itsourcecode 1 Online Admission System 2026-10-06 6.3 Medium
A flaw has been found in itsourcecode Online Admission System 1.0. This impacts an unknown function of the file /new.php. Executing a manipulation of the argument schedid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
CVE-2026-105182 1 Sourcecodester 1 Online Reviewer Management System 2026-10-06 7.3 High
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
CVE-2026-105178 1 Sourcecodester 1 Drug Recommendation System 2026-10-06 4.7 Medium
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-105149 1 Moosocial 1 Moosocial 2026-10-06 7.3 High
A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-105166 1 Kishor-23 2 Food-waste-management-system, Food Waste Management System 2026-10-06 7.3 High
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-39764 2 Radiustheme, Wordpress-extensions 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
CVE-2026-39771 2 Mightynetworks Vs Buddyboss, Wordpress-extensions 2 Buddyboss Platform, Buddyboss Platform 2026-10-06 8.5 High
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
CVE-2026-39785 2 Serhii Pasiuk, Wordpress-extensions 2 Gmedia Photo Gallery, Gmedia Photo Gallery 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
CVE-2026-39795 2 Brewlabs, Wordpress-extensions 2 Sendpress Newsletters, Sendpress Newsletters 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
CVE-2026-41555 2 Weblizar, Wordpress-extensions 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
CVE-2026-95865 2 Beaverbuilder, Wordpress-extensions 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder 2026-10-06 6.5 Medium
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type.
CVE-2026-71298 2 Maestro, Redhat 3 Maestro, Multicluster Engine, Multicluster Engine For Kubernetes 2026-10-06 6.4 Medium
A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.
CVE-2026-42414 2 Cridio, Wordpress-extensions 2 Listingpro, Listingpro 2026-10-06 8.5 High
Subscriber SQL Injection in ListingPro <= 2.9.12 versions.
CVE-2026-42415 2 Portotheme, Wordpress-extensions 2 Functionality, Porto Theme 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
CVE-2026-42416 2 Andondesign, Wordpress-extensions 2 Udesign, Udesign Core 2026-10-06 8.5 High
Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.
CVE-2026-42417 2 Reputeinfosystems, Wordpress-extensions 2 Armember, Armember Premium 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
CVE-2026-105317 2 Cozmoslabs, Wordpress-extensions 2 Paid Member Subscriptions, Paid Member Subscriptions 2026-10-06 8.5 High
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
CVE-2026-105919 1 Kusalkasilva 1 Learning-management-system 2026-10-06 7.3 High
A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-76570 2 Joomcode, Joomcoder.com 2 Jc Tables, Jctables Extension For Joomla 2026-10-06 9.1 Critical
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.