140 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-61667 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1 | CRITICAL | 9.9 | 50%ile | NVD | 2026-09-15 |
| CVE-2026-52630 | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEdito | CRITICAL | 9.8 | 40%ile | NVD | 2026-09-11 |
| CVE-2026-82232 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. | CRITICAL | 9.8 | 46%ile | NVD | 2026-09-14 |
| CVE-2026-86460 | Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue | CRITICAL | 9.8 | 45%ile | NVD | 2026-09-14 |
| CVE-2026-77051 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. | CRITICAL | 9.8 | 46%ile | NVD | 2026-09-14 |
| CVE-2026-76461 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthentic | CRITICAL | 9.8 | 80%ile | NVD | 2026-09-14 |
| CVE-2026-67100 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. w | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-18 |
| CVE-2026-17543 | SQL injection in ext-pgsql via E'...' backslash breakout | CRITICAL | 9.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2024-58385 | Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo | CRITICAL | 9.3 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-79752 | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::ca | CRITICAL | 9.2 | 39%ile | NVD | 2026-09-17 |
| CVE-2026-20284 | A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection | CRITICAL | 9.1 | 33%ile | NVD | 2026-09-16 |
| CVE-2026-75513 | Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marte | CRITICAL | 9.1 | 29%ile | NVD | 2026-09-16 |
| CVE-2026-8462 | SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allo | HIGH | 8.9 | 47%ile | NVD | 2026-09-16 |
| CVE-2026-55416 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticat | HIGH | 8.8 | 48%ile | NVD | 2026-09-14 |
| CVE-2026-61701 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until | HIGH | 8.8 | 43%ile | NVD | 2026-09-14 |
| CVE-2026-20361 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | HIGH | 8.8 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-87105 | Tanium addressed a SQL injection vulnerability in Threat Response. | HIGH | 8.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-20344 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote | HIGH | 8.8 | 31%ile | NVD | 2026-09-16 |
| CVE-2026-15741 | PostgreSQL expression deparse allows SQL injection via EXTRACT argument | HIGH | 8.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-6637 | PostgreSQL refint allows stack buffer overflow and SQL injection | HIGH | 8.8 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-89180 | EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote atta | HIGH | 8.7 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-82028 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API serv | HIGH | 8.7 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-81567 | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0- | HIGH | 8.7 | 14%ile | NVD | 2026-09-15 |
| CVE-2026-80491 | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL qu | HIGH | 8.6 | 26%ile | NVD | 2026-09-12 |
| CVE-2026-84047 | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it | HIGH | 8.6 | 18%ile | NVD | 2026-09-12 |
| CVE-2026-78375 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Fre | HIGH | 8.6 | 13%ile | NVD | 2026-09-14 |
| CVE-2026-15600 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotio | HIGH | 8.6 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-7848 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProdu | HIGH | 8.6 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-78472 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it | HIGH | 8.6 | 36%ile | NVD | 2026-09-16 |
| CVE-2026-87963 | The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before u | HIGH | 8.6 | 26%ile | NVD | 2026-09-17 |
| CVE-2026-87767 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef | HIGH | 8.6 | 9%ile | NVD | 2026-09-18 |
| CVE-2026-87770 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using | HIGH | 8.6 | 9%ile | NVD | 2026-09-18 |
| CVE-2026-87771 | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them | HIGH | 8.6 | 9%ile | NVD | 2026-09-18 |
| CVE-2026-87774 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to | HIGH | 8.6 | 9%ile | NVD | 2026-09-18 |
| CVE-2026-87775 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to | HIGH | 8.6 | 9%ile | NVD | 2026-09-18 |
| CVE-2026-55072 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objec | HIGH | 8.5 | 31%ile | NVD | 2026-09-14 |
| CVE-2026-81894 | Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-im | HIGH | 8.5 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-81895 | In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] withou | HIGH | 8.5 | 14%ile | NVD | 2026-09-15 |
| CVE-2026-66580 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | HIGH | 8.5 | 18%ile | NVD | 2026-09-17 |
| CVE-2026-93292 | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints tha | HIGH | 8.4 | 23%ile | NVD | 2026-09-17 |
| CVE-2026-93426 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, | HIGH | 8.4 | 31%ile | NVD | 2026-09-17 |
| CVE-2026-54597 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi | HIGH | 8.3 | 24%ile | NVD | 2026-09-17 |
| CVE-2026-92903 | Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be int | HIGH | 8.2 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-54354 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tran | HIGH | 8.2 | 35%ile | NVD | 2026-09-17 |
| CVE-2026-54596 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi | HIGH | 8.1 | 28%ile | NVD | 2026-09-17 |
| CVE-2026-53557 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use | HIGH | 7.7 | 19%ile | NVD | 2026-09-17 |
| CVE-2026-18912 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allo | HIGH | 7.7 | 73%ile | NVD | 2026-09-18 |
| CVE-2026-62109 | Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-11 |
| CVE-2026-62112 | Editor SQL Injection in Amelia <= 2.4.9 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-11 |
| CVE-2026-92465 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Me | HIGH | 7.6 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-76425 | A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks | HIGH | 7.6 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-66618 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66619 | Administrator SQL Injection in Newsletters <= 4.18 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66624 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66625 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66626 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66628 | Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66630 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-66631 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | HIGH | 7.6 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-16482 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection v | HIGH | 7.5 | 28%ile | NVD | 2026-09-12 |
| CVE-2026-20247 | A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affe | HIGH | 7.5 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-15275 | The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc | HIGH | 7.5 | 31%ile | NVD | 2026-09-18 |
| CVE-2026-18442 | The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti | HIGH | 7.5 | 42%ile | NVD | 2026-09-18 |
| CVE-2026-85705 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API | HIGH | 7.5 | 27%ile | NVD | 2026-09-18 |
| CVE-2026-87212 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-86865 | Tanium addressed a SQL injection vulnerability in Asset. | HIGH | 7.2 | 24%ile | NVD | 2026-09-16 |
| CVE-2026-87024 | Tanium addressed a SQL injection vulnerability in Asset. | HIGH | 7.2 | 24%ile | NVD | 2026-09-16 |
| CVE-2026-54646 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator | HIGH | 7.2 | 72%ile | NVD | 2026-09-17 |
| CVE-2026-54647 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t | HIGH | 7.2 | 72%ile | NVD | 2026-09-17 |
| CVE-2026-93591 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values | HIGH | 7.2 | — | NVD | 2026-09-18 |
| CVE-2026-20300 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affect | HIGH | 7.1 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-52851 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an ob | HIGH | 7.1 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-54524 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the | HIGH | 7.1 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-77927 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract | HIGH | 7.1 | — | NVD | 2026-09-18 |
| CVE-2026-77928 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract | HIGH | 7.1 | — | NVD | 2026-09-18 |
| CVE-2026-85188 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Condition | MEDIUM | 6.9 | 13%ile | NVD | 2026-09-14 |
| CVE-2026-16593 | The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them | MEDIUM | 6.8 | 14%ile | NVD | 2026-09-15 |
| CVE-2026-76556 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values | MEDIUM | 6.8 | 31%ile | NVD | 2026-09-16 |
| CVE-2026-76557 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration | MEDIUM | 6.8 | 31%ile | NVD | 2026-09-16 |
| CVE-2026-77161 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter | MEDIUM | 6.5 | 19%ile | NVD | 2026-09-12 |
| CVE-2026-85198 | The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic S | MEDIUM | 6.5 | 22%ile | NVD | 2026-09-12 |
| CVE-2026-16588 | The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versi | MEDIUM | 6.5 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-84859 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search e | MEDIUM | 6.5 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-84993 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 a | MEDIUM | 6.5 | 41%ile | NVD | 2026-09-16 |
| CVE-2026-17576 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, | MEDIUM | 6.5 | 20%ile | NVD | 2026-09-18 |
| CVE-2026-17607 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the | MEDIUM | 6.5 | 28%ile | NVD | 2026-09-18 |
| CVE-2026-85652 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio | MEDIUM | 6.5 | 35%ile | NVD | 2026-09-18 |
| CVE-2026-4036 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in | MEDIUM | 6.5 | 27%ile | NVD | 2026-09-18 |
| CVE-2026-53556 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat | MEDIUM | 6.0 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-36989 | A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. | MEDIUM | 5.8 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90495 | A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance- | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-13 |
| CVE-2026-90514 | A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-13 |
| CVE-2026-90515 | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unkn | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-13 |
| CVE-2026-90516 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown f | MEDIUM | 5.5 | 35%ile | NVD | 2026-09-13 |
| CVE-2026-90526 | A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unk | MEDIUM | 5.5 | 37%ile | NVD | 2026-09-13 |
| CVE-2026-90701 | A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a | MEDIUM | 5.5 | 35%ile | NVD | 2026-09-14 |
| CVE-2026-90708 | A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file | MEDIUM | 5.5 | 17%ile | NVD | 2026-09-14 |
| CVE-2026-90789 | A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown funct | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-90805 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Th | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-90841 | A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is a | MEDIUM | 5.5 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-90844 | A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90846 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the fi | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90849 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by th | MEDIUM | 5.5 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-90854 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90855 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown f | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90876 | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is | MEDIUM | 5.5 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-90877 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90879 | A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-91004 | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown | MEDIUM | 5.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-91848 | A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of | MEDIUM | 5.5 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-92366 | A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search | MEDIUM | 5.5 | 40%ile | NVD | 2026-09-16 |
| CVE-2026-92405 | A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element i | MEDIUM | 5.5 | 35%ile | NVD | 2026-09-16 |
| CVE-2026-92406 | A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown f | MEDIUM | 5.5 | 35%ile | NVD | 2026-09-16 |
| CVE-2026-92926 | A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepar | MEDIUM | 5.5 | 19%ile | NVD | 2026-09-17 |
| CVE-2026-32599 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database | MEDIUM | 5.3 | 18%ile | NVD | 2026-09-15 |
| CVE-2020-15875 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf | MEDIUM | 5.0 | 21%ile | NVD | 2026-09-13 |
| CVE-2026-20235 | A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view | MEDIUM | 4.9 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-76426 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct | MEDIUM | 4.9 | 28%ile | NVD | 2026-09-16 |
| CVE-2026-76428 | A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct | MEDIUM | 4.9 | 31%ile | NVD | 2026-09-16 |
| CVE-2026-76448 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a | MEDIUM | 4.9 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-76449 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a | MEDIUM | 4.9 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-75961 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the | MEDIUM | 4.9 | 32%ile | NVD | 2026-09-18 |
| CVE-2026-6638 | PostgreSQL REFRESH PUBLICATION allows SQL injection via table name | LOW | 3.7 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-13683 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler | LOW | 2.7 | 17%ile | NVD | 2026-09-18 |
| CVE-2026-90511 | A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerabil | LOW | 2.1 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90525 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the f | LOW | 2.1 | 27%ile | NVD | 2026-09-13 |
| CVE-2026-90574 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of | LOW | 2.1 | 25%ile | NVD | 2026-09-13 |
| CVE-2026-90597 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an un | LOW | 2.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90600 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the f | LOW | 2.1 | 11%ile | NVD | 2026-09-13 |
| CVE-2026-90700 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown functi | LOW | 2.1 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90796 | A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file | LOW | 2.1 | 17%ile | NVD | 2026-09-14 |
| CVE-2026-92364 | A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown | LOW | 2.1 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-92526 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/ | LOW | 2.1 | 10%ile | NVD | 2026-09-16 |
| CVE-2026-90496 | A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_orde | LOW | 2.0 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-92221 | A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affecte | LOW | 2.0 | 19%ile | NVD | 2026-09-16 |
| CVE-2026-79303 | kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without t | UNKNOWN | — | 12%ile | NVD | 2026-09-15 |
| CVE-2025-55787 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. | UNKNOWN | — | 5%ile | NVD | 2026-09-17 |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | UNKNOWN | — | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-41889 | pgx: SQL Injection via placeholder confusion with dollar quoted string literals | UNKNOWN | — | 29%ile | Microsoft | 2026-05-12 |
| Security Advisory 0145 | Security Advisory 0145 | UNKNOWN | — | — | Arista | 2026-07-27 |