Export limit exceeded: 21139 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21139 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16950 | 2026-08-19 | 8.6 High | ||
| The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks. | ||||
| CVE-2019-25751 | 1 Cmsjunkie | 2 Classifiedsmanager, J-classifiedsmanager | 2026-08-19 | 8.2 High |
| Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the displayads component to extract sensitive database information including usernames, databases, and version details. | ||||
| CVE-2026-19631 | 1 Tenable | 1 Security Center | 2026-08-19 | 4.9 Medium |
| A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials. | ||||
| CVE-2026-19680 | 1 Tenable | 1 Security Center | 2026-08-19 | 7.1 High |
| A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | ||||
| CVE-2017-20264 | 1 Pulseextensions | 1 Sponsor Wall | 2026-08-19 | 7.1 High |
| Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_sponsorwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information including credentials and configuration data. | ||||
| CVE-2017-20265 | 1 Pulseextensions | 1 Flip Wall | 2026-08-19 | 7.1 High |
| Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information. | ||||
| CVE-2026-19919 | 1 Code-projects | 1 Online Shopping System | 2026-08-19 | 7.3 High |
| A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | ||||
| CVE-2026-19905 | 1 Jinher | 1 Oa | 2026-08-19 | 7.3 High |
| A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-19894 | 1 Itsourcecode | 1 Hospital Management System | 2026-08-19 | 6.3 Medium |
| A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewmedicine.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2017-20267 | 2 Joomla, Joomlathat | 2 Calendar Planner, Calendar Planner | 2026-08-19 | 8.2 High |
| Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information. | ||||
| CVE-2017-20252 | 1 Nextgeneditor | 1 Nextgen Editor | 2026-08-19 | 8.2 High |
| Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information. | ||||
| CVE-2017-20274 | 1 King-products | 2 Learning Management System King, Lms King Professional | 2026-08-19 | 8.2 High |
| Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and task=learningPath parameters to extract sensitive database information. | ||||
| CVE-2023-0946 | 1 Mayurik | 1 Best Pos Management System | 2026-08-19 | 6.3 Medium |
| A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The identifier VDB-221593 was assigned to this vulnerability. | ||||
| CVE-2023-3617 | 1 Mayurik | 1 Best Pos Management System | 2026-08-19 | 7.3 High |
| A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233565 was assigned to this vulnerability. | ||||
| CVE-2023-27204 | 1 Mayurik | 1 Best Pos Management System | 2026-08-19 | 9.8 Critical |
| Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php. | ||||
| CVE-2023-27203 | 1 Mayurik | 1 Best Pos Management System | 2026-08-19 | 9.8 Critical |
| Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php. | ||||
| CVE-2023-27202 | 1 Mayurik | 1 Best Pos Management System | 2026-08-19 | 9.8 Critical |
| Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php. | ||||
| CVE-2023-27205 | 1 Mayurik | 1 Best Pos Management System | 2026-08-19 | 9.8 Critical |
| Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php. | ||||
| CVE-2017-20255 | 1 Joombooking | 1 Jb Visa | 2026-08-19 | 8.2 High |
| Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters, injecting SQL commands in the visatype parameter to extract sensitive database information including credentials and table contents. | ||||
| CVE-2017-20258 | 1 Extro | 2 Responsive Portfolio, Rpc | 2026-08-19 | 8.2 High |
| Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract sensitive database information. | ||||