Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

20,274 CVEs tagged with CWE-894,544 Critical, 8,504 High, 6,245 Medium, 980 Low, 1 Unrated.

CVE-2026-6230

Published Jul 8, 2026

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escapi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-12936

Published Jul 8, 2026

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.…

CVSS 4.9 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-9700

Published Jul 8, 2026

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-55635

Published Jul 7, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated S…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-33734

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter function…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14471

Published Jul 6, 2026

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated…

CVSS 8.6 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-14809

Published Jul 6, 2026

Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database content…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-14799

Published Jul 6, 2026

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the a…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14798

Published Jul 6, 2026

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. T…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14797

Published Jul 6, 2026

A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Exe…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14796

Published Jul 6, 2026

A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation o…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14795

Published Jul 6, 2026

A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-vis…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14774

Published Jul 5, 2026

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /paymentdischarge.php. This manipulation of the argumen…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14773

Published Jul 5, 2026

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /payment.php. The manipulation of the argument patientid res…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14772

Published Jul 5, 2026

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an unknown function of the file /edit_course1.php. The manipu…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-14771

Published Jul 5, 2026

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The affected element is an unknown function of the file /edit_exam1.php. Executing a manipulat…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-14770

Published Jul 5, 2026

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_room.php. Performing a manipulation of the…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-14769

Published Jul 5, 2026

A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argu…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-14768

Published Jul 5, 2026

A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument lo…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-14767

Published Jul 5, 2026

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14766

Published Jul 5, 2026

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-res…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-14764

Published Jul 5, 2026

A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Managem…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-14763

Published Jul 5, 2026

A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-14762

Published Jul 5, 2026

A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Man…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-14756

Published Jul 5, 2026

A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0
Showing 551-575 of 20,274 CVEsPage 23 of 811