Search Results (38086 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-25426 1 Guchengwuyue 1 Yshopmall 2025-06-12 7.2 High
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
CVE-2025-26047 1 Olajowon 1 Loggrove 2025-06-12 5.1 Medium
Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
CVE-2025-45240 1 Qianfox 1 Foxcms 2025-06-12 6.5 Medium
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.
CVE-2025-4327 1 Mrcms 1 Mrcms 2025-06-12 4.3 Medium
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.
CVE-2025-44073 1 Seacms 1 Seacms 2025-06-12 9.8 Critical
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2024-11269 1 Mitchelllevy 1 Ahathat 2025-06-12 7.2 High
The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.
CVE-2024-11267 1 Joomlaserviceprovider 1 Jsp Store Locator 2025-06-12 8.8 High
The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.
CVE-2025-26842 1 Znuny 1 Znuny 2025-06-12 7.5 High
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.
CVE-2025-47785 1 Emlog 1 Emlog 2025-06-12 8.3 High
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this will cause SQL injection to occur when the registered site is enabled, resulting in the injection of the admin account and password, which is then exploited by the backend remote code execution. As of time of publication, it is unknown whether a fix exists.
CVE-2025-2203 1 Funnelkit 1 Funnel Builder 2025-06-12 6.1 Medium
The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CVE-2024-9879 1 Melapress 1 Melapress File Monitor 2025-06-12 5.4 Medium
The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CVE-2024-9838 1 Flamescorpion 1 Auto Affiliate Links 2025-06-12 5.4 Medium
The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CVE-2024-9831 1 Taskbuilder 1 Taskbuilder 2025-06-12 7.2 High
The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CVE-2025-28202 1 Govicture 2 Rx1800, Rx1800 Firmware 2025-06-12 8.8 High
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.
CVE-2025-4863 1 Advayasoftech 1 Gems Erp Portal 2025-06-12 6.3 Medium
A vulnerability, which was classified as critical, was found in Advaya Softech GEMS ERP Portal 2.1. This affects an unknown part of the file /studentLogin/studentLogin.action. The manipulation of the argument userId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4940 1 1000projects 1 Daily College Class Work Report Book 2025-06-12 7.3 High
A vulnerability, which was classified as critical, has been found in 1000 Projects Daily College Class Work Report Book 1.0. This issue affects some unknown processing of the file /admin_info.php. The manipulation of the argument batch leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-41231 1 Vmware 1 Cloud Foundation 2025-06-12 7.3 High
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.
CVE-2025-26086 1 Rsiqueue 1 Management System 2025-06-12 7.5 High
An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
CVE-2025-5857 1 Fabianros 1 Patient Record Management System 2025-06-12 6.3 Medium
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. The manipulation of the argument itr_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-25308 1 Code-projects 1 Simple School Management System 2025-06-12 8.8 High
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.