Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

20,147 CVEs tagged with CWE-894,513 Critical, 8,464 High, 6,204 Medium, 964 Low, 2 Unrated.

CVE-2026-58376

Published Jun 30, 2026

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying…

CVSS 7.2 · High
evidence mentions
4
Buzz score
22.6

CVE-2025-53648

Published Jun 30, 2026

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, whi…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-8402

Published Jun 30, 2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 600…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-53690

Published Jun 30, 2026

An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The application fails to sanitize us…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-13766

Published Jun 30, 2026

DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constru…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-9711

Published Jun 30, 2026

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and includ…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-12076

Published Jun 30, 2026

Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL statemen…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57955

Published Jun 29, 2026

SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the…

CVSS 8.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-13752

Published Jun 29, 2026

Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulne…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13746

Published Jun 29, 2026

Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying crafted valu…

CVSS 3.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13744

Published Jun 29, 2026

Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project c…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13579

Published Jun 29, 2026

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executi…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13578

Published Jun 29, 2026

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Perf…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13572

Published Jun 29, 2026

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation o…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-40524

Published Jun 29, 2026

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN()…

CVSS 7.2 · High
evidence mentions
4
Buzz score
25.6

CVE-2026-40523

Published Jun 29, 2026

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute…

CVSS 7.2 · High
evidence mentions
4
Buzz score
25.6

CVE-2026-40522

Published Jun 29, 2026

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by…

CVSS 7.1 · High
evidence mentions
4
Buzz score
25.6

CVE-2026-13569

Published Jun 29, 2026

A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component API. Such manipul…

CVSS 2.0 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-13566

Published Jun 29, 2026

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /preview3.php. The manipul…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13565

Published Jun 29, 2026

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_class1.p…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13559

Published Jun 29, 2026

A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13555

Published Jun 29, 2026

A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?acti…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13552

Published Jun 29, 2026

A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Perf…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13551

Published Jun 29, 2026

A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulat…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13550

Published Jun 29, 2026

A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulatio…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0
Showing 526-550 of 20,147 CVEsPage 22 of 806