Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,915 CVEs tagged with CWE-894,433 Critical, 8,389 High, 6,143 Medium, 949 Low, 1 Unrated.

CVE-2025-61024

Published Jun 23, 2026

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High

CVE-2026-44792

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control c…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34914

Published Jun 23, 2026

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform bli…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-61028

Published Jun 23, 2026

An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-61027

Published Jun 23, 2026

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High

CVE-2025-61025

Published Jun 23, 2026

An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High

CVE-2025-61023

Published Jun 23, 2026

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-61022

Published Jun 23, 2026

An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High

CVE-2025-61021

Published Jun 23, 2026

An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High

CVE-2025-61020

Published Jun 23, 2026

An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2025-61019

Published Jun 23, 2026

An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High

CVE-2025-61018

Published Jun 23, 2026

An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54313

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Fi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54310

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted paramete…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52673

Published Jun 23, 2026

SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-56221

Published Jun 22, 2026

Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are interpolated directly into SQL que…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-44272

Published Jun 22, 2026

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44271

Published Jun 22, 2026

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7253

Published Jun 22, 2026

IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the att…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66336

Published Jun 22, 2026

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query i…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2026-12789

Published Jun 21, 2026

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/cl…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-12776

Published Jun 21, 2026

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This man…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12775

Published Jun 21, 2026

A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2019-25761

Published Jun 19, 2026

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through th…

CVSS 7.1 · High

CVE-2019-25759

Published Jun 19, 2026

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the…

CVSS 7.1 · High
Showing 401-425 of 19,915 CVEsPage 17 of 797