Export limit exceeded: 25258 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 21091 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (21091 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-4889 | 1 Rdl Technologies | 1 Eloanapp Platform | 2026-10-06 | N/A |
| SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries. | ||||
| CVE-2026-105918 | 1 Kusalkasilva | 1 Learning-management-system | 2026-10-06 | 7.3 High |
| A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-42417 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. | ||||
| CVE-2026-42416 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | ||||
| CVE-2026-42415 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. | ||||
| CVE-2026-42414 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in ListingPro <= 2.9.12 versions. | ||||
| CVE-2026-41555 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | ||||
| CVE-2026-39795 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | ||||
| CVE-2026-39785 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | ||||
| CVE-2026-39771 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | ||||
| CVE-2026-39764 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | ||||
| CVE-2026-39747 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in Woffice <= 5.4.35 versions. | ||||
| CVE-2026-39746 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. | ||||
| CVE-2026-32581 | 2026-10-06 | 7.1 High | ||
| Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions. | ||||
| CVE-2026-32580 | 2026-10-06 | 7.5 High | ||
| Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions. | ||||
| CVE-2026-32557 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. | ||||
| CVE-2026-25434 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions. | ||||
| CVE-2026-105317 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | ||||
| CVE-2026-104389 | 2026-10-06 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5. | ||||
| CVE-2026-103355 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-06 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||