By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 13 of 86
- CVE-2016-20069HIGH 8.2
WordPress Booking Calendar Contact Form version 1.0.23 contains a flaw that allows unauthenticated attackers to inject malicious SQL commands through the calendar shortcode parameter. Because the plugin fails to properly validate and sanitize user input before passing it to database queries, attackers can execute arbitrary SQL statements to read sensitive data from the WordPress database without needing credentials or user interaction.
- CVE-2016-20071HIGH 8.2
The 404 Redirection Manager plugin version 1.0 for WordPress has a serious flaw that allows attackers to steal data directly from your WordPress database without needing to log in. An attacker can send a specially crafted web request containing SQL commands, which the plugin fails to validate, leading to unauthorized database access. This is a remote vulnerability that requires no authentication and can be exploited from anywhere on the internet.
- CVE-2016-20072HIGH 8.2
A critical security flaw exists in the BBS e-Franchise 1.1.1 WordPress plugin that allows attackers to steal sensitive data directly from your WordPress database without needing to log in. The vulnerability is in how the plugin handles the `uid` parameter—attackers can inject malicious SQL commands that trick the database into revealing user accounts, passwords, and other sensitive information. This is a classic SQL injection attack delivered through web requests to pages using the plugin's shortcode functionality.
- CVE-2016-20073HIGH 8.2
A WordPress plugin called Answer My Question version 1.3 contains a flaw that lets attackers without user accounts inject malicious database commands. By sending specially crafted requests to a specific plugin file, attackers can read sensitive information from the WordPress database, including site configuration and taxonomy data. The vulnerability requires no user interaction and can be exploited remotely over the network.
- CVE-2017-20243HIGH 8.2
The WordPress Car Park Booking Plugin version from October 17 contains a SQL injection flaw that allows attackers to directly manipulate the plugin's database queries without authentication. By crafting malicious requests with specially crafted parameters, attackers can extract sensitive information from the WordPress database, such as user credentials, booking details, and other confidential records. The vulnerability is exploited through time-based SQL injection techniques, where attackers observe database response delays to infer data values.
- CVE-2017-20244HIGH 8.2
The Wow Forms WordPress plugin version 2.1 has a critical flaw that lets attackers steal sensitive information directly from a website's database without needing to log in. By sending specially crafted requests to the plugin's form-handling endpoint, an attacker can inject malicious SQL commands through the form ID parameter, bypassing the plugin's security controls and reading any database content they want—including user credentials, email addresses, and other confidential data.
- CVE-2017-20245HIGH 8.2
The Wow Viral Signups WordPress plugin version 2.1 contains a SQL injection flaw that allows attackers to steal data directly from your website's database without needing to log in. An attacker can craft a malicious request to the WordPress admin-ajax.php endpoint, inject SQL commands into the 'idsignup' parameter, and read sensitive information such as user credentials, email addresses, and other stored data. The vulnerability is trivial to trigger and requires no special privileges.
- CVE-2017-20246HIGH 8.2
The KittyCatfish 2.2 WordPress plugin contains a critical SQL injection flaw that allows anyone on the internet to steal data directly from the affected website's database without needing to log in. An attacker can manipulate a web request parameter to inject malicious SQL commands, then extract sensitive information—usernames, passwords, email addresses, or other stored data—by observing subtle timing differences or boolean responses from the server. No authentication or user interaction is required.
- CVE-2017-20247HIGH 8.2
WordPress sites running the PICA Photo Gallery plugin version 1.0 are vulnerable to SQL injection attacks. An attacker can manipulate the 'aid' parameter in GET requests to execute unauthorized database queries without needing to log in. This allows extraction of sensitive data such as WordPress user credentials and other database contents, posing a direct threat to site integrity and user privacy.
- CVE-2017-20249HIGH 8.2
Apptha Slider Gallery version 1.0 contains a critical SQL injection flaw that lets attackers without any authentication bypass the application and extract sensitive data directly from the database. By crafting malicious requests with poisoned parameters, attackers can pull user credentials and password hashes. The vulnerability requires no user interaction and is trivially easy to exploit over the network.
- CVE-2017-20252HIGH 8.2
Joomla's NextGen Editor extension version 2.1.0 contains an SQL injection flaw that lets attackers bypass authentication and directly query the site's database. An unauthenticated attacker can craft a malicious web request targeting the plname parameter to extract sensitive data—including user credentials, configuration details, or other confidential information stored in the database. The attack requires no special user privileges or interaction, making it straightforward to exploit over the network.
- CVE-2017-20253HIGH 8.2
A critical flaw exists in Joomla! Component My Projects version 2.0 that allows attackers to inject malicious SQL commands without requiring authentication. By manipulating the VerAyari parameter in requests to the component, attackers can execute arbitrary database queries, potentially exposing usernames, passwords, and other sensitive system information stored in the database.
- CVE-2017-20254HIGH 8.2
Joomla! Component User Bench version 1.0 has a critical flaw that allows attackers to read sensitive database information without logging in. By crafting a specially formed web request, an attacker can inject malicious SQL commands into the userid parameter, potentially exposing usernames, passwords, and system configuration data stored in the application's database. No authentication or user interaction is required to attempt this attack.
- CVE-2017-20255HIGH 8.2
Joomla! Component JB Visa version 1.0 contains a critical SQL injection flaw that lets unauthenticated attackers query the application's database directly. By crafting malicious GET requests to specific Joomla parameters, an attacker can extract sensitive data—usernames, passwords, email addresses, and other database contents—without needing to log in. The vulnerability requires only network access and a properly formed HTTP request, making it relatively straightforward to exploit.
- CVE-2017-20256HIGH 8.2
Joomla Survey Force Deluxe version 3.2.4 contains a SQL injection flaw accessible without authentication. Attackers can craft malicious web requests to the vulnerable component and inject SQL commands through a parameter called 'invite,' allowing them to query and extract data directly from the underlying database. This is a straightforward injection attack requiring no user interaction or credentials.
- CVE-2017-20257HIGH 8.2
Joomla! Component Quiz Deluxe version 3.7.4 contains an SQL injection flaw that allows attackers to send malicious database commands without authentication. By crafting specially formatted requests to the component's quiz flagging feature, an attacker can read sensitive data from the database, such as user credentials, quiz answers, or other protected information. This vulnerability requires no user interaction or credentials to exploit.
- CVE-2017-20258HIGH 8.2
A SQL injection flaw in Joomla! Component RPC Responsive Portfolio version 1.6.1 allows attackers without credentials to retrieve sensitive database information. By crafting a specially-formulated web request, an attacker can inject malicious SQL commands through the component's portfolio item ID parameter, potentially exposing user data, credentials, or other confidential records stored in the application's database.
- CVE-2017-20259HIGH 8.2
Joomla's OSDownloads extension version 1.7.4 contains an SQL injection flaw that allows attackers to run arbitrary database commands without authentication. By crafting malicious requests to the item view, attackers can read sensitive data like database credentials and configuration settings directly from the backend.
- CVE-2017-20260HIGH 8.2
A SQL injection flaw in Joomla! Component Price Alert version 3.0.2 allows attackers to inject malicious database commands through the product_id parameter without needing to authenticate. By targeting the subscribeajax view with specially crafted requests, attackers can extract sensitive information from the database, including user credentials and system configuration details. The vulnerability is straightforward to exploit and carries significant risk to any site running the affected component version.
- CVE-2017-20261HIGH 8.2
Joomla! installations running the Bargain Product VM3 component version 1.0 are vulnerable to unauthenticated SQL injection attacks. An attacker can craft malicious SQL commands within web requests and send them to specific component views to extract sensitive data directly from the underlying database. No authentication or user interaction is required—the vulnerability is remotely exploitable over the network.
- CVE-2017-20262HIGH 8.2
A SQL injection flaw in Joomla's Ajax Quiz component version 1.8 allows attackers to inject malicious database commands through web requests without needing to log in. By crafting specially formatted URLs, an attacker can extract sensitive information directly from the underlying database, such as table names, user credentials, and other confidential data. The vulnerability is straightforward to exploit over the network and requires no user interaction.
- CVE-2017-20263HIGH 8.2
A vulnerability in the Joomla! FocalPoint Pro/Free component (version 1.2.3) allows attackers to inject SQL commands into website databases without authentication. By crafting a malicious web request with a specially prepared ID parameter, an attacker can extract sensitive data such as user credentials, customer information, or other confidential records stored in the database. This is a remote attack that requires no special access or user interaction—any unauthenticated person on the internet can exploit it.
- CVE-2017-20266HIGH 8.2
Joomla SP Movie Database version 1.3 contains a flaw that allows attackers on the internet to steal sensitive data from the database without needing a login. An attacker can craft a malicious search query that tricks the database into executing unintended commands, exposing information like user credentials, private content, or system details. The vulnerability is accessed through the search feature, making it easy for attackers to discover and exploit.
- CVE-2017-20267HIGH 8.2
The Joomla! Calendar Planner component version 1.0.1 suffers from an SQL injection flaw that allows attackers to execute arbitrary SQL queries without authentication. By crafting malicious GET requests to the events view with specially crafted SQL code in the category_id parameter, an attacker can bypass database access controls and extract sensitive information directly from the underlying database. This vulnerability is particularly concerning because it requires no user interaction, no prior access, and can be exploited by anyone with network connectivity to the affected system.
- CVE-2017-20268HIGH 8.2
Joomla! Component Zap Calendar Lite version 4.3.4 contains an SQL injection flaw that allows attackers to bypass authentication entirely and extract sensitive database information. By crafting malicious SQL commands and sending them through a specific plugin parameter, an unauthenticated attacker can enumerate database names, table structures, and potentially retrieve confidential data. The vulnerability requires no special access, no user interaction, and can be exploited remotely over the network.
- CVE-2017-20269HIGH 8.2
Joomla! users running the KissGallery component version 1.0.0 face a serious security risk. The component fails to properly validate user input in its URL handling, allowing attackers to inject malicious SQL commands without any authentication. An attacker can craft a specially designed URL targeting the kissgallery endpoint and extract sensitive data directly from the database. This is a remote, unauthenticated attack that requires no user interaction—a significant concern for any Joomla deployment hosting this component.
- CVE-2017-20270HIGH 8.2
A SQL injection vulnerability exists in Joomla!'s Twitch TV component (version 1.1) that allows attackers to bypass authentication entirely and directly manipulate database queries. By crafting malicious requests through the username and id parameters, an unauthenticated attacker can extract sensitive information from the underlying database—including user credentials, API keys, and system configuration data. The vulnerability requires no user interaction and can be exploited remotely by anyone with network access to the affected Joomla instance.
- CVE-2017-20271HIGH 8.2
A vulnerability in Joomla StreetGuessr Game version 1.1.8 allows attackers to inject SQL commands through a web request without needing login credentials. By manipulating the catid parameter in a specially crafted URL, attackers can extract sensitive information from the underlying database, including version details and database names. This is a classic SQL injection flaw that requires no user interaction and can be exploited remotely over the network.
- CVE-2017-20272HIGH 8.2
Joomla Ultimate Property Listing version 1.0.2 contains an SQL injection flaw that allows attackers to bypass authentication entirely and query the application's database directly. By crafting malicious requests to the component's listing view, an attacker can extract sensitive data such as table names, column structures, and potentially user information or financial records stored in the database. No special access, account, or user interaction is required to exploit this vulnerability.
- CVE-2017-20273HIGH 8.2
Joomla Event Registration Pro Calendar version 4.1.3 has a SQL injection flaw that allows attackers to inject malicious database commands through the id parameter in web requests. An attacker can craft a specially formatted GET request to expose sensitive data stored in the database without needing to log in or interact with legitimate users. The vulnerability requires only network access and no special conditions to exploit.
- CVE-2017-20274HIGH 8.2
Joomla LMS King Professional version 3.2.4.0 contains an SQL injection flaw that lets unauthenticated attackers manipulate the underlying database without authentication. An attacker can craft a malicious web request targeting the learning path feature, injecting SQL commands through a specific parameter to read sensitive data from the database. This doesn't require the attacker to be logged in or interact with a user—it's a direct attack on the application's database layer.
- CVE-2017-20275HIGH 8.2
Joomla! websites running the PHP-Bridge component version 1.2.3 are vulnerable to SQL injection attacks. An attacker can craft a malicious web request to extract sensitive database information without needing any credentials. By manipulating the id parameter in a GET request, an attacker gains read access to database tables, column names, and potentially usernames, passwords, or other sensitive data stored in the database.
- CVE-2017-20276HIGH 8.2
A SQL injection vulnerability exists in Joomla!'s SIMGenealogy component (version 2.1.5) that allows attackers to bypass authentication and extract sensitive database information. By crafting malicious GET requests to the component's latest-view endpoint, unauthenticated attackers can inject SQL commands through the type parameter, potentially exposing user data, credentials, or other confidential information stored in the database. This is a network-accessible, remotely exploitable flaw requiring no user interaction.
- CVE-2017-20277HIGH 8.2
The Joomla JoomRecipe component version 1.0.4 contains a SQL injection flaw in its search functionality. An unauthenticated attacker can craft malicious search requests to extract sensitive data from the underlying database without triggering obvious errors—a technique called blind SQL injection. The vulnerability requires no user interaction and is exploitable over the network, making it a meaningful risk for sites running this component.
- CVE-2017-20278HIGH 8.2
JoomRecipe, a Joomla component, contains a flaw that allows attackers to inject malicious SQL commands through the category parameter when requesting recipe lists. An unauthenticated attacker can craft a specially formed web request to extract sensitive information from the underlying database without needing valid login credentials. The vulnerability affects version 1.0.3 and is exploitable over the network with no complex prerequisites.
- CVE-2017-20279HIGH 8.2
Joomla Payage version 2.05 contains a SQL injection flaw in its payment processing functionality. An attacker can craft malicious web requests containing specially crafted SQL code in the payment ID parameter, allowing unauthorized database access without needing to log in. Using this vulnerability, an attacker could extract sensitive information from the underlying database using blind SQL injection techniques—either observing timing differences in responses or true/false patterns—to gradually exfiltrate data.
- CVE-2017-20280HIGH 8.2
The Joomla Myportfolio component version 3.0.2 contains a flaw that allows attackers to inject malicious SQL commands into database queries without needing to log in. By crafting specially formatted web requests to a specific endpoint, an attacker can retrieve sensitive information stored in the database. This is a remote attack that requires no authentication and no user interaction.
- CVE-2017-20281HIGH 8.2
A SQL injection vulnerability exists in Joomla's Extra Search component (version 2.2.8) that allows attackers to query and extract sensitive data from affected databases without authentication. By crafting malicious GET requests to the component's search functionality, an attacker can bypass normal data access controls and retrieve information that should remain confidential—such as user credentials, email addresses, or other sensitive records stored in the database.
- CVE-2017-20282HIGH 8.2
The Joomla! jCart component for OpenCart 2.0 is vulnerable to SQL injection—a flaw that allows attackers to send specially crafted requests that trick the application into executing unintended database commands. An unauthenticated attacker can exploit this by manipulating the product_id parameter in GET requests, potentially extracting sensitive information from the underlying database without any authentication or user interaction required. The vulnerability is network-accessible and carries a high severity rating due to the ease of exploitation and the confidentiality risk it poses.
- CVE-2018-25382HIGH 8.2
Zechat 1.5 contains an SQL injection flaw in its profile.php endpoint that allows attackers to inject malicious SQL commands through the username parameter without authentication. By crafting specially formatted requests, an attacker can extract database structure information and sensitive data directly from the application's backend database.
- CVE-2018-25385HIGH 8.2
E-Registrasi Pencak Silat version 18.10 contains an SQL injection flaw that allows attackers without credentials to retrieve sensitive data from the application's database. By crafting malicious requests to the monitor_nilai.php endpoint, an attacker can inject SQL commands through the id_partai parameter to extract admin credentials, user records, and other protected information. No authentication is required to attempt this attack.
- CVE-2018-25386HIGH 8.2
HaPe PKH 1.1 contains multiple SQL injection flaws in its admin media management interface that allow attackers to inject malicious SQL commands and extract sensitive database information. Unauthenticated attackers can target the village module, while authenticated users can exploit several administrative modules. The vulnerability stems from improper handling of the 'id' parameter, enabling attackers to manipulate database queries and retrieve system-level data such as database credentials, names, and DBMS version details.
- CVE-2018-25389HIGH 8.2
HaPe PKH 1.1 is vulnerable to SQL injection through the 'nama_kelompok' parameter in the lap-anggota-kelompok-pdf.php endpoint. An attacker can send a specially crafted request without authentication to execute arbitrary SQL commands, enabling extraction of sensitive database information using time-based blind techniques. This is a direct-to-database attack that bypasses application logic entirely.
- CVE-2018-25390HIGH 8.2
HaPe PKH 1.1 is vulnerable to SQL injection through its lap-peserta-perdesa-pdf.php endpoint. An attacker can send a specially crafted request containing SQL code in the 'desa' POST parameter to manipulate database queries without authentication. Using time-based blind SQL injection techniques, an adversary can extract sensitive information from the underlying database by observing query response delays.
- CVE-2018-25394HIGH 8.2
Kados R10 GreenBee contains an SQL injection flaw that allows attackers without authentication to read sensitive database information by crafting malicious web requests. The vulnerability exists in a administrative function that fails to properly validate user input, enabling an attacker to embed SQL commands directly into the system's database queries. This could expose usernames, database names, and system version details.
- CVE-2018-25395HIGH 8.2
Kados R10 GreenBee contains a critical SQL injection flaw in its board feature management interface. An attacker without authentication can craft a specially formatted web request targeting the feature update function to inject arbitrary SQL commands directly into the database. This allows the attacker to read sensitive data like database credentials, user information, and system details—potentially exposing the entire database to compromise.
- CVE-2018-25398HIGH 8.2
CVE-2018-25398 is an unauthenticated SQL injection vulnerability in Open ISES Project version 3.30A. An attacker can craft malicious database queries and submit them through the frm_passwd parameter in POST requests to main.php, bypassing authentication entirely. This allows extraction of sensitive database contents—usernames, database names, system versions—without needing valid credentials. The vulnerability is remotely exploitable with no special conditions required.
- CVE-2018-25399HIGH 8.2
Open ISES Project version 3.30A contains an SQL injection flaw in its nearby.php endpoint that lets unauthenticated attackers inject malicious SQL commands through two URL parameters: tick_lat and tick_lng. An attacker can craft a simple GET request to extract sensitive information from the underlying database, such as usernames, database identifiers, and version numbers. No authentication is required, and exploitation is straightforward—making this a high-severity issue for any organization running this software.
- CVE-2018-25400HIGH 8.2
Open ISES Project version 3.30A contains an unauthenticated SQL injection vulnerability in its form submission endpoint. An attacker can craft malicious SQL code and send it through a web request to extract sensitive information from the application's database without needing valid credentials. The vulnerability requires no user interaction and can be exploited over the network, making it a significant remote threat.
- CVE-2018-25401HIGH 8.2
Open ISES Project version 3.30A is vulnerable to SQL injection through an unauthenticated web interface. An attacker can craft malicious database queries and send them via HTTP GET requests to the sever_graph.php endpoint, bypassing authentication entirely. This allows extraction of sensitive database schema and contents without legitimate access.
- CVE-2018-25402HIGH 8.2
Open ISES Project version 3.30A contains an SQL injection vulnerability accessible to unauthenticated attackers over the network. By crafting malicious SQL statements in the p1 parameter of GET requests to inc_types_graph.php, an attacker can query the underlying database directly, potentially exposing schema details, user records, and other sensitive stored data. The vulnerability requires no authentication or user interaction, making it relatively straightforward to exploit.
- CVE-2018-25403HIGH 8.2
A SQL injection vulnerability exists in Open ISES Project version 3.30A that allows attackers without authentication to inject malicious database commands through a web parameter. By crafting specially designed requests to the city_graph.php file, attackers can extract sensitive information from the underlying database, including schema details and other stored data. The vulnerability requires no user interaction and can be exploited over the network.
- CVE-2018-25404HIGH 8.2
Open ISES Project version 3.30A is vulnerable to SQL injection through its add_facnote.php endpoint. An attacker can craft malicious SQL code in the ticket_id parameter and send it via a GET request without needing to authenticate first. This allows the attacker to read sensitive data directly from the database, including version information and other confidential records. The vulnerability requires no special conditions—any internet-connected instance of the software is at risk.
- CVE-2018-25405HIGH 8.2
eNdonesia Portal version 8.7 is vulnerable to multiple SQL injection flaws that allow unauthenticated attackers to extract sensitive data directly from the database. An attacker can manipulate specific web parameters—artid, cid, did, contid, and aboutid in the mod.php file—to inject malicious SQL commands. This bypasses normal authentication and gives direct access to usernames, database credentials, and system version information without requiring any valid user account.
- CVE-2018-25406HIGH 8.2
eNdonesia Portal version 8.7 contains multiple SQL injection flaws that allow attackers without authentication to run arbitrary database commands. By inserting malicious SQL code into specific URL parameters—artid, cid, did, contid, and aboutid—across five different modules (publisher, diskusi, galeri, content, and about), attackers can extract sensitive information like database credentials and system version details. This is a network-based attack requiring no user interaction or prior access.
- CVE-2018-25407HIGH 8.2
eNdonesia Portal version 8.7 contains multiple SQL injection flaws in its mod.php file that allow attackers to inject malicious SQL commands without authentication. By crafting specially formed requests targeting parameters like artid, cid, did, contid, and aboutid across various portal modules (publisher, diskusi, galeri, content, about), an attacker can extract sensitive database information such as usernames, database names, and version details. No user interaction or authentication is required to exploit this vulnerability.
- CVE-2018-25411HIGH 8.2
MGB OpenSource Guestbook version 0.7.0.2 contains a flaw that allows attackers to inject malicious database commands into the application without needing to log in. By sending specially crafted web requests to the email.php file with harmful code embedded in the 'id' parameter, an attacker can read sensitive information directly from the database—including the names of tables and columns that store user data. This vulnerability requires no authentication, making it trivial for an external attacker to exploit.
- CVE-2018-25413HIGH 8.2
AiOPMSD Final version 1.0.0 contains an SQL injection flaw that allows attackers to execute unauthorized database queries without authentication. By crafting malicious SQL statements and sending them through the application's search function (search.php), an attacker can extract sensitive information such as database credentials, usernames, and system details. This is a network-based attack requiring no user interaction or special privileges.
- CVE-2018-25414HIGH 8.2
AiOPMSD Final version 1.0.0 contains a straightforward but serious SQL injection flaw in its actor.php endpoint. An attacker can craft malicious SQL code and send it through the actor parameter via a simple GET request—no authentication required—to execute arbitrary database queries. This allows them to extract sensitive information like database credentials, usernames, and version details directly from the backend database.
- CVE-2018-25415HIGH 8.2
AiOPMSD Final version 1.0.0 contains an unauthenticated SQL injection flaw in its director.php endpoint. An attacker can craft a malicious URL with SQL code injected into the director parameter and send it as a simple GET request—no login required. Once executed, the attacker gains unauthorized access to the database, potentially exposing usernames, database names, system version information, and other sensitive data. The vulnerability is trivial to trigger and requires no special tools or user interaction.
- CVE-2018-25416HIGH 8.2
AiOPMSD Final version 1.0.0 contains a SQL injection flaw that allows anyone on the internet to query the application's database directly without logging in. An attacker can craft malicious requests to the country.php endpoint to extract sensitive information such as usernames, database names, and version numbers. This is a straightforward injection attack—the application fails to sanitize user input before passing it to SQL queries.
- CVE-2018-25417HIGH 8.2
AiOPMSD Final 1.0.0 contains an unauthenticated SQL injection flaw in the quality.php endpoint. An attacker can craft a malicious GET request with a SQL payload in the quality parameter to run arbitrary SQL commands against the backend database, potentially exposing usernames, database identifiers, and version information without requiring any authentication or user interaction.
- CVE-2018-25418HIGH 8.2
AiOPMSD Final version 1.0.0 contains an SQL injection vulnerability in its year parameter that allows attackers to execute arbitrary database queries without authentication. By crafting malicious SQL code and sending it through GET requests to the year.php endpoint, an attacker can extract sensitive information such as usernames, database names, and database version details. The vulnerability requires no user interaction and can be exploited over the network by any unauthenticated actor.
- CVE-2018-25419HIGH 8.2
AiOPMSD Final 1.0.0 suffers from a critical SQL injection flaw in its genre parameter. An attacker can craft a malicious URL to genre.php and extract sensitive data—usernames, database names, version information—without needing to authenticate. The vulnerability is straightforward to exploit over the network and poses a real risk to confidentiality of stored data.
- CVE-2018-25420HIGH 8.2
AiOPMSD Final version 1.0.0 contains an SQL injection flaw that lets attackers query the application's database without needing any credentials. By crafting malicious SQL code into web requests targeting the watch.php endpoint, an attacker can extract sensitive data like user credentials and database structure information. The vulnerability requires no authentication, no special interaction from a victim, and poses a direct threat to data confidentiality.
- CVE-2018-25422HIGH 8.2
MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the id parameter in play.php. Attackers can craft malicious GET requests to extract sensitive data like usernames and other database information without needing authentication.
- CVE-2018-25424HIGH 8.2
Gate Pass Management System version 2.1 contains an SQL injection flaw in its login mechanism that allows attackers to bypass authentication entirely without knowing valid credentials. By crafting malicious SQL code into the login and password fields of the application's login form, an unauthenticated attacker can trick the system into granting access. This is a critical weakness because the login page is typically the first line of defense, and compromising it gives attackers full entry to the application and any data it manages.
- CVE-2018-25425HIGH 8.2
Yot CMS version 3.3.1 contains an unauthenticated SQL injection vulnerability accessible through HTTP GET requests. An attacker can manipulate the 'aid' or 'cid' URL parameters to inject arbitrary SQL commands, potentially exposing sensitive database information without requiring any authentication or user interaction. The vulnerability is network-accessible and relatively straightforward to exploit.
- CVE-2018-25428HIGH 8.2
Paroiciel version 11.20 contains an unauthenticated SQL injection flaw in its trec.php endpoint. An attacker can craft malicious web requests to the tRecIdListe parameter, inject arbitrary SQL commands, and retrieve sensitive database contents like table and column names without needing valid credentials. This is a remote attack that requires no special privileges or user interaction.
- CVE-2018-25433HIGH 8.2
The JE Photo Gallery component for Joomla version 1.1 contains a critical flaw that allows attackers to inject malicious SQL commands without needing credentials. By manipulating a parameter in web requests, attackers can extract sensitive information directly from the database, including user credentials. This vulnerability requires no authentication or user interaction, making it particularly dangerous for websites using this component.
- CVE-2018-25434HIGH 8.2
WP AutoSuggest version 0.24 contains a critical SQL injection flaw that lets attackers bypass authentication entirely and query your WordPress database directly. By sending specially crafted requests to the plugin's autosuggest.php endpoint, an attacker can extract sensitive data—posts, user information, and other database contents—without needing any WordPress account or permissions. This is particularly dangerous because the vulnerability requires no user interaction and is trivial to exploit remotely.
- CVE-2019-25726HIGH 8.2
All in One Video Downloader version 1.2 contains an SQL injection flaw that lets attackers query the application's database without authentication. By crafting malicious requests to the admin interface, adversaries can extract sensitive information like user credentials and database structure details. The vulnerability requires no special access or user interaction—attackers can exploit it remotely over the network.
- CVE-2019-25728HIGH 8.2
Care2x 2.7 contains a flaw that lets attackers bypass authentication entirely and read sensitive database information by modifying a cookie called ck_config. An attacker on the internet can craft a malicious request without any credentials to trick the application into executing unauthorized database queries. The vulnerability affects login pages and module endpoints, making it a straightforward way to extract private data.
- CVE-2019-25730HIGH 8.2
Listing Hub CMS version 1.0 contains a SQL injection flaw that allows attackers without credentials to run arbitrary database commands. By sending specially crafted requests to the pages.php file with malicious values in the id parameter, attackers can extract sensitive information such as database credentials and system version details. The vulnerability requires no authentication or user interaction, making it a straightforward attack vector for anyone with network access to the affected application.
- CVE-2019-25732HIGH 8.2
PHP EI-Tube Script 3 contains a flaw that allows attackers to inject malicious commands into the application's search function without needing any credentials. By crafting specially designed search queries, an attacker can trick the application into executing unauthorized database commands, potentially exposing usernames, passwords, and other sensitive information stored in the database.
- CVE-2019-25745HIGH 8.2
The Google Review Slider WordPress plugin version 6.1 contains a SQL injection flaw that allows attackers to execute unauthorized database queries without needing to log in. By crafting malicious requests targeting the 'tid' parameter, an attacker can gradually extract sensitive data from a WordPress site's database using time-based blind SQL injection—a technique where database response delays confirm whether injected queries are true or false. This vulnerability poses a direct risk to any WordPress installation running the affected plugin version.
- CVE-2019-25748HIGH 8.2
Joomla JHotelReservation version 6.0.7 contains an SQL injection vulnerability in its hotel search functionality. An attacker can craft malicious requests to the search-hotels endpoint, injecting SQL commands through the rooms parameter without authentication, enabling unauthorized access to sensitive database information such as version details. This is a serious flaw because it requires no user interaction, no authentication, and can be exploited remotely over the network.
- CVE-2019-25750HIGH 8.2
Joomla websites using the J-MultipleHotelReservation component (version 6.0.7) are vulnerable to SQL injection attacks. An attacker can send specially crafted requests to the hotel search function and inject malicious SQL commands that execute on the database. This doesn't require authentication, meaning anyone on the internet can attempt the attack. The primary risk is unauthorized access to sensitive data stored in the database, such as customer information, booking details, or other confidential records.
- CVE-2019-25751HIGH 8.2
Joomla's J-ClassifiedsManager component version 3.0.5 contains a critical flaw that allows attackers to inject malicious SQL commands without authentication. By crafting specific requests targeting the classifieds display feature, an attacker can bypass normal database safeguards and extract sensitive information like usernames, database names, and version details. This vulnerability requires no special privileges or user interaction—an attacker with network access can exploit it directly.
- CVE-2019-25752HIGH 8.2
A critical flaw in Joomla!'s J-BusinessDirectory component (version 4.9.7) allows attackers to inject malicious SQL code without needing to log in. By crafting a specially formatted web request, an attacker can trick the component into revealing sensitive database information such as table names, user credentials, and other confidential data. The vulnerability is exposed through a specific web parameter called 'type' in the component's category-retrieval function, making it simple for attackers to exploit remotely.
- CVE-2019-25753HIGH 8.2
A SQL injection vulnerability in Joomla! Component VMap version 1.9.6 allows attackers to execute arbitrary database queries without authentication. By crafting malicious requests containing SQL code in the latlngbound parameter, an attacker can manipulate how the component queries the database, potentially exposing sensitive information stored in your Joomla installation. The vulnerability is accessible via standard HTTP GET requests and requires no user interaction or prior system access.
- CVE-2019-25754HIGH 8.2
A SQL injection vulnerability exists in Joomla Component vRestaurant version 1.9.4 that allows unauthenticated attackers to execute arbitrary SQL commands. By sending specially crafted POST requests to the menu-listing-layout endpoint with malicious code in the keysearch parameter, attackers can bypass security controls and extract sensitive database information without any authentication. This is a direct-access attack requiring only network connectivity to the vulnerable component.
- CVE-2019-25755HIGH 8.2
Joomla's vReview component version 1.9.11 has a critical flaw that allows attackers to inject SQL commands through a web form parameter. An unauthenticated attacker can craft malicious requests to the editReview endpoint and extract sensitive data like user credentials and database structure without needing to log in or interact with a legitimate user.
- CVE-2019-25756HIGH 8.2
Joomla! Component vAccount version 2.0.2 contains a critical SQL injection flaw in its expense dashboard feature. An attacker without authentication can craft malicious requests to the vaccount-dashboard/expense endpoint, injecting SQL code through the vid parameter to query and extract sensitive database information like version numbers and database names. The vulnerability requires only network access and no user interaction, making it straightforward to exploit.
- CVE-2021-4478HIGH 8.2
Dräger CC-Vision Basic (versions before 7.5.3) and Dräger CC-Vision E-Cal (versions before 7.2.5.0) are vulnerable to a buffer overflow when processing specially crafted .gdt files. An attacker can create a malicious file that, when opened by a user, causes the application to crash or potentially execute arbitrary code on the system. The vulnerability requires user interaction—someone must open the malicious file—but does not require elevated privileges to trigger.
- CVE-2021-4480HIGH 8.2
Dräger Protector Software before version 6.4.2 has a local privilege escalation flaw rooted in overly permissive file system permissions. An attacker with local access to an affected system can replace critical binaries or loaded modules, then trigger execution with NT SYSTEM privileges—the highest level of access on Windows. This gives an adversary complete control over the host.
- CVE-2021-4481HIGH 8.2
Dräger Protector Software versions prior to 6.4.2 suffer from a local privilege escalation flaw rooted in overly permissive file system permissions. An attacker with local access to an affected system can exploit this weakness to replace system binaries or loaded modules, ultimately executing arbitrary code with the highest privilege level (NT SYSTEM). This is a boots-on-the-ground attack: the attacker must have local file system access, but once they do, they can gain complete system control.
- CVE-2023-29146HIGH 8.2
Malwarebytes EDR 1.0.11 on Linux contains a flaw in how it calculates cryptographic hashes of data. When processing files or data larger than 4GB, the hashing function incorrectly truncates the input, causing the hash calculation to wrap around. This means an attacker with elevated privileges could craft two different data sets that produce the same hash value—a collision. Because hash matching is often used to verify file integrity or authenticate data, this vulnerability could allow an attacker to bypass security controls or forge trusted content.
- CVE-2025-53831HIGH 8.2
DrawIO for ownCloud contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts into the application. When other users view content created by an attacker, the injected script executes in their browser with their privileges, potentially compromising their accounts or sensitive data. The vulnerability stems from insufficient input validation when generating web pages. An attacker needs valid access to the DrawIO app to exploit it, but the resulting attack affects any user who interacts with the malicious content.
- CVE-2025-69755HIGH 8.2
A vulnerability in the Neterbit NW-431F Router (firmware version NW-431F-20241014-IR03) allows attackers on the network to read sensitive information and run unauthorized commands on the device. An attacker can send specially crafted requests to the router's at_command.asp interface without needing credentials or user interaction, making this a direct and urgent threat to any organization using this model.
- CVE-2026-10560HIGH 8.2
IBM Langflow OSS versions 1.0.0 through 1.9.6 have a flaw that allows anyone on the internet to access job build information and stop running jobs without needing a password or authentication token. An attacker only needs a valid job identifier to read sensitive build event data or cancel active jobs, leading to information leakage and service disruption.
- CVE-2026-10564HIGH 8.2
IBM Langflow, an open-source low-code platform, contains a Server-Side Request Forgery (SSRF) vulnerability in versions 1.0.0 through 1.9.6. Two components—RSSReaderComponent and SearXNG—fail to validate URLs before making HTTP requests, allowing authenticated attackers to access internal systems. An attacker could reach cloud metadata services (such as AWS, Azure, or GCP IMDS endpoints) to steal IAM credentials, or probe internal networks. The issue is particularly concerning because agentic workflows can be manipulated via prompt injection to trigger these requests automatically.
- CVE-2026-10622HIGH 8.2
Collibra Agent contains a flaw in how it authenticates users to its REST API. The vulnerability allows someone from the internet to call administrative functions through REST endpoints without providing valid credentials. An attacker can exploit this to gain unauthorized access to sensitive functionality that should be restricted to authenticated administrators.
- CVE-2026-12473HIGH 8.2
OHIF (Open Health Imaging Foundation), a widely-used web-based medical imaging platform, contains a vulnerability in two of its default data source components—DICOMWebProxy and DICOMJSON—that allows attackers to redirect authentication tokens to malicious servers. When a user accesses OHIF through these data sources, the platform automatically attaches their authenticated session credentials to requests sent to attacker-controlled URLs, exposing sensitive authentication tokens without the user's knowledge or consent. The standard DICOMweb data source is not affected. An attacker needs only to craft a malicious link or compromise a configuration to exploit this, making it a significant token theft vector for healthcare organizations using OHIF in its default setup.
- CVE-2026-14336HIGH 8.2
PIA contains a flawed validation mechanism for OIDC token issuers that allows an attacker to bypass its allowlist protections. Instead of properly validating that an issuer URL belongs to a trusted host, PIA performs a simple text prefix match. An attacker can craft a malicious issuer URL that passes this check while actually directing token validation and JWKS key fetches to an attacker-controlled server. This allows unauthenticated attackers to inject forged authentication tokens, potentially gaining unauthorized access to PIA's SBOM upload endpoint.
- CVE-2026-14637HIGH 8.2
A critical flaw has been discovered in the Ecommerce-CodeIgniter-Bootstrap project that allows attackers to remotely execute arbitrary code by manipulating how the shopping cart data is processed. The vulnerability exploits unsafe deserialization—a process where untrusted data is converted back into executable objects without proper validation. An attacker can send a specially crafted shopping cart parameter to trigger this flaw, potentially compromising the application and any data it handles. The exploit details have already been made public, making this an active threat.
- CVE-2026-24088HIGH 8.2
CVE-2026-24088 is a cryptographic flaw in Qualcomm wireless and networking chipsets that allows a high-privileged attacker to bypass security controls and load a custom bootloader onto affected devices. The vulnerability stems from improper validation during firmware partition processing, enabling unauthorized modification of the boot sequence. This could allow an attacker with administrative or hardware-level access to inject malicious code that executes before the operating system, potentially taking complete control of the device.
- CVE-2026-24751HIGH 8.2
Kiteworks, a platform used to securely share and manage sensitive business data, contains a reflected cross-site scripting (XSS) vulnerability in its Secure Data Forms feature. An attacker can craft a malicious link that, when clicked by a legitimate user, causes the victim's browser to execute arbitrary JavaScript code within the context of the Kiteworks application. This could allow the attacker to steal session cookies, impersonate the user, or perform unauthorized actions on their behalf. The vulnerability affects all versions of Kiteworks prior to 9.3.0.
- CVE-2026-24752HIGH 8.2
Kiteworks, a private data network platform, contains a reflected cross-site scripting (XSS) flaw in its Secure Data Forms component that could allow an attacker to inject malicious JavaScript. An attacker could craft a deceptive link and trick a user into clicking it, causing the user's browser to execute arbitrary code in the context of their Kiteworks session. This is a social engineering attack vector rather than a direct infrastructure compromise, but the impact can be severe if the victim has administrative or sensitive data access.
- CVE-2026-27771HIGH 8.2
Gitea, a self-hosted Git service, has a vulnerability that allows unauthenticated attackers to view sensitive information about private package sources used in Composer (a PHP dependency manager). An attacker can access details about internal or private package repositories without needing credentials, potentially exposing server names, URLs, and authentication tokens embedded in package configuration. This affects Gitea versions 1.26.1 and earlier.