116 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-48330 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL | CRITICAL | 10.0 | 49%ile | NVD | 2026-08-03 |
| CVE-2026-52887 | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE | CRITICAL | 10.0 | 45%ile | GitHub | 2026-07-31 |
| CVE-2026-63232 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro | CRITICAL | 9.9 | 22%ile | NVD | 2026-07-29 |
| CVE-2026-63233 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro | CRITICAL | 9.9 | 22%ile | NVD | 2026-07-29 |
| CVE-2026-63234 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro | CRITICAL | 9.9 | 22%ile | NVD | 2026-07-29 |
| CVE-2026-58046 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL inject | CRITICAL | 9.9 | 27%ile | NVD | 2026-07-30 |
| CVE-2026-69083 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable | CRITICAL | 9.9 | 28%ile | NVD | 2026-08-03 |
| CVE-2026-69084 | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement | CRITICAL | 9.9 | 21%ile | NVD | 2026-08-03 |
| CVE-2026-69085 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s | CRITICAL | 9.9 | 16%ile | NVD | 2026-08-03 |
| CVE-2026-48326 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL | CRITICAL | 9.9 | 39%ile | NVD | 2026-08-03 |
| CVE-2026-54658 | Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/u | CRITICAL | 9.8 | 32%ile | NVD | 2026-07-28 |
| CVE-2025-65340 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-29 |
| CVE-2025-67403 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-29 |
| CVE-2025-67404 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-29 |
| CVE-2025-69942 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-29 |
| CVE-2025-69943 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and | CRITICAL | 9.8 | 20%ile | NVD | 2026-07-29 |
| CVE-2026-4978 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-65336 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | CRITICAL | 9.8 | 24%ile | NVD | 2026-07-30 |
| CVE-2025-69930 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69931 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69933 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69934 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69935 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69936 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69937 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69938 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69941 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69947 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. | CRITICAL | 9.8 | 18%ile | NVD | 2026-07-30 |
| CVE-2025-69946 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr | CRITICAL | 9.8 | 26%ile | NVD | 2026-07-31 |
| CVE-2025-69948 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. | CRITICAL | 9.8 | 23%ile | NVD | 2026-07-31 |
| CVE-2026-69240 | Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl | CRITICAL | 9.8 | 24%ile | NVD | 2026-08-03 |
| CVE-2026-15721 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig | CRITICAL | 9.8 | 14%ile | NVD | 2026-08-04 |
| CVE-2026-6881 | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a | CRITICAL | 9.4 | 10%ile | NVD | 2026-07-28 |
| CVE-2026-63221 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v | CRITICAL | 9.4 | 30%ile | NVD | 2026-07-31 |
| CVE-2026-17351 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu | CRITICAL | 9.4 | 37%ile | NVD | 2026-07-31 |
| CVE-2026-58048 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | CRITICAL | 9.4 | 40%ile | NVD | 2026-07-31 |
| CVE-2025-67649 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input | CRITICAL | 9.3 | 20%ile | NVD | 2026-07-31 |
| CVE-2026-65321 | PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar | CRITICAL | 9.3 | 36%ile | NVD | 2026-08-02 |
| CVE-2026-18801 | OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2026-65890 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthe | CRITICAL | 9.2 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-63229 | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time- | CRITICAL | 9.1 | 22%ile | NVD | 2026-07-29 |
| CVE-2026-63230 | A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read | CRITICAL | 9.1 | 22%ile | NVD | 2026-07-29 |
| CVE-2026-51992 | SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code | CRITICAL | 9.1 | 41%ile | NVD | 2026-07-29 |
| CVE-2026-13596 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied paramete | CRITICAL | 9.1 | 18%ile | NVD | 2026-08-01 |
| CVE-2026-12965 | The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befo | CRITICAL | 9.1 | 25%ile | NVD | 2026-08-03 |
| CVE-2026-16532 | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using | CRITICAL | 9.1 | 18%ile | NVD | 2026-08-03 |
| CVE-2026-50736 | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscrib | CRITICAL | 9.0 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-5490 | DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privi | HIGH | 8.8 | 39%ile | NVD | 2026-07-29 |
| CVE-2026-6637 | PostgreSQL refint allows stack buffer overflow and SQL injection | HIGH | 8.8 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-8339 | A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus | HIGH | 8.7 | 10%ile | NVD | 2026-07-29 |
| CVE-2026-54368 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows | HIGH | 8.7 | 32%ile | NVD | 2026-07-30 |
| CVE-2026-17346 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin | HIGH | 8.7 | 36%ile | NVD | 2026-07-31 |
| CVE-2026-41453 | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use | HIGH | 8.7 | 28%ile | NVD | 2026-08-03 |
| CVE-2026-48448 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL | HIGH | 8.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-13395 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a | HIGH | 8.6 | 26%ile | NVD | 2026-07-30 |
| CVE-2026-22620 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau | HIGH | 8.6 | 29%ile | NVD | 2026-07-30 |
| CVE-2026-12721 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us | HIGH | 8.6 | 18%ile | NVD | 2026-07-31 |
| CVE-2025-67650 | An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio | HIGH | 8.6 | 20%ile | NVD | 2026-07-31 |
| CVE-2026-46593 | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input | HIGH | 8.6 | 22%ile | NVD | 2026-07-31 |
| CVE-2026-16572 | The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a | HIGH | 8.6 | 20%ile | NVD | 2026-08-03 |
| CVE-2026-39931 | OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t | HIGH | 8.6 | 25%ile | NVD | 2026-08-03 |
| CVE-2026-64631 | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | HIGH | 8.5 | — | NVD | 2026-08-04 |
| CVE-2026-7769 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM | HIGH | 8.1 | 20%ile | NVD | 2026-07-28 |
| CVE-2026-63231 | A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based | HIGH | 8.1 | 17%ile | NVD | 2026-07-29 |
| CVE-2026-17543 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f | HIGH | 8.1 | 31%ile | NVD | 2026-07-30 |
| CVE-2026-15258 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe | HIGH | 8.1 | 13%ile | NVD | 2026-07-31 |
| CVE-2026-16539 | The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S | HIGH | 8.1 | 13%ile | NVD | 2026-08-03 |
| CVE-2025-67405 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param | HIGH | 7.3 | 7%ile | NVD | 2026-07-29 |
| CVE-2025-67406 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu | HIGH | 7.3 | 10%ile | NVD | 2026-07-29 |
| CVE-2025-67407 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters | HIGH | 7.3 | 7%ile | NVD | 2026-07-29 |
| CVE-2025-67408 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter | HIGH | 7.3 | 7%ile | NVD | 2026-07-29 |
| CVE-2025-69945 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. | HIGH | 7.3 | 7%ile | NVD | 2026-07-29 |
| CVE-2025-69949 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em | HIGH | 7.3 | 7%ile | NVD | 2026-07-29 |
| CVE-2026-12895 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries | HIGH | 7.1 | 12%ile | NVD | 2026-07-29 |
| CVE-2026-15929 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma | HIGH | 7.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-18737 | Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL | HIGH | 7.1 | 15%ile | NVD | 2026-08-03 |
| CVE-2026-39879 | SQL injection in syslog-ng SQL destionation driver | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-15153 | The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative | MEDIUM | 6.8 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-48121 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto | MEDIUM | 6.7 | — | NVD | 2026-08-04 |
| CVE-2026-15304 | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions | MEDIUM | 6.5 | 16%ile | NVD | 2026-07-28 |
| CVE-2026-16092 | The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi | MEDIUM | 6.5 | 16%ile | NVD | 2026-07-30 |
| CVE-2026-14554 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them | MEDIUM | 6.5 | 14%ile | NVD | 2026-07-31 |
| CVE-2026-16087 | The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec | MEDIUM | 6.5 | 19%ile | NVD | 2026-08-01 |
| CVE-2026-6453 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi | MEDIUM | 6.5 | 20%ile | NVD | 2026-08-01 |
| CVE-2026-11391 | Tanium addressed a SQL injection vulnerability in Patch. | MEDIUM | 6.3 | 8%ile | NVD | 2026-07-28 |
| CVE-2024-36039 | PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict | MEDIUM | 6.3 | 49%ile | Microsoft | 2024-05-14 |
| CVE-2026-45376 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3 | MEDIUM | 5.5 | 27%ile | NVD | 2026-07-31 |
| CVE-2026-15018 | The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor | MEDIUM | 5.3 | 18%ile | NVD | 2026-08-01 |
| CVE-2026-33385 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig | MEDIUM | 5.1 | 15%ile | NVD | 2026-07-29 |
| CVE-2026-15344 | The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver | MEDIUM | 4.9 | 28%ile | NVD | 2026-07-29 |
| CVE-2026-11973 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a | MEDIUM | 4.9 | 22%ile | NVD | 2026-07-29 |
| CVE-2026-15403 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame | MEDIUM | 4.9 | 19%ile | NVD | 2026-08-01 |
| CVE-2026-15951 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and | MEDIUM | 4.9 | 19%ile | NVD | 2026-08-01 |
| CVE-2026-16614 | The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL | MEDIUM | 4.9 | 19%ile | NVD | 2026-08-01 |
| CVE-2026-17555 | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers | MEDIUM | 4.9 | 19%ile | NVD | 2026-08-01 |
| CVE-2026-62845 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv | MEDIUM | 4.7 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-15381 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S | LOW | 3.7 | 8%ile | NVD | 2026-07-31 |
| CVE-2026-6638 | PostgreSQL REFRESH PUBLICATION allows SQL injection via table name | LOW | 3.7 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-18719 | A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo | LOW | 2.1 | 9%ile | NVD | 2026-08-04 |
| CVE-2026-18766 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect | LOW | 2.1 | — | NVD | 2026-08-04 |
| CVE-2026-18592 | A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of | LOW | 2.0 | 10%ile | NVD | 2026-08-03 |
| CVE-2025-69944 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie | UNKNOWN | — | 4%ile | NVD | 2026-07-29 |
| CVE-2026-51775 | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati | UNKNOWN | — | 4%ile | NVD | 2026-08-03 |
| CVE-2026-52521 | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th | UNKNOWN | — | 4%ile | NVD | 2026-08-03 |
| CVE-2026-14872 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e | UNKNOWN | — | 5%ile | NVD | 2026-08-04 |
| CVE-2026-70369 | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con | UNKNOWN | — | — | NVD | 2026-08-04 |
| CVE-2026-70370 | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu | UNKNOWN | — | — | NVD | 2026-08-04 |
| CVE-2026-70371 | Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request | UNKNOWN | — | — | NVD | 2026-08-04 |
| CVE-2026-70372 | Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa | UNKNOWN | — | — | NVD | 2026-08-04 |
| CVE-2026-70373 | Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc | UNKNOWN | — | — | NVD | 2026-08-04 |
| CVE-2026-41889 | pgx: SQL Injection via placeholder confusion with dollar quoted string literals | UNKNOWN | — | 28%ile | Microsoft | 2026-05-12 |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | UNKNOWN | — | 36%ile | Microsoft | 2026-05-12 |
| Security Advisory 0145 | Security Advisory 0145 | UNKNOWN | — | — | Arista | 2026-07-27 |
| FG-IR-26-132 | SQL command injection in administrative portal | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-134 | User controlled SQL commands | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-102 | Multiple SQL Injections | UNKNOWN | — | — | Fortinet | 2026-04-14 |