VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

810 CVEsRSS

CVE-2026-87105High· 8.8
1w ago

Tanium addressed a SQL injection vulnerability in Threat Response.

Tanium addressed a SQL injection vulnerability in Threat Response.

▾ TwilightTanium · Threat ResponseEPSS 0.43%via NVD
CVE-2026-92406High· 7.3PoC
1w ago

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argum…

▾ MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.43%via NVD
CVE-2026-92405High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The …

▾ MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.43%via NVD
CVE-2026-84993Medium· 6.5
1w ago

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate its direction value…

▾ Sunlitmikro-orm · mikro-ormEPSS 0.51%via NVD
CVE-2026-20344High· 8.8
1w ago

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker mu…

▾ TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.37%via NVD
CVE-2026-76428Medium· 4.9
1w ago

A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concate…

A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concate…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.48%via NVD
CVE-2026-76426Medium· 4.9
1w ago

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of spe…

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of spe…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.48%via NVD
CVE-2026-76425High· 7.6
1w ago

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are …

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are …

▾ TwilightCisco · Cisco Identity Services Engine SoftwareEPSS 0.41%via NVD
CVE-2026-20361High· 8.8
1w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ TwilightCisco · Cisco Nexus DashboardEPSS 0.28%via NVD
CVE-2026-20300High· 7.1
1w ago

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. …

▾ TwilightCisco · Cisco Identity Services Engine SoftwareEPSS 0.29%via NVD
CVE-2026-20247High· 7.5
1w ago

A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input

A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit th…

▾ TwilightCisco · Cisco Identity Services Engine SoftwareEPSS 0.32%via NVD
CVE-2026-20235Medium· 4.9
1w ago

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrat…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.29%via NVD
CVE-2026-76449Medium· 4.9
1w ago

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerabili…

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerabili…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.43%via NVD
CVE-2026-76448Medium· 4.9
1w ago

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerabili…

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerabili…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.43%via NVD
CVE-2026-92366High· 7.3PoC
1w ago

A vulnerability was determined in code-projects Matrimonial System 1.0

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.56%via NVD
CVE-2026-84859Medium· 6.5
1w ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQ…

▾ SunlitScada-LTS · Scada-LTSEPSS 0.36%via NVD
CVE-2026-92364Medium· 6.3PoC
1w ago

A vulnerability has been found in itsourcecode Leave Management System 1.0

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-92465High· 7.6
1w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

▾ TwilightThemeum · wp-megamenuEPSS 0.38%via NVD
CVE-2026-8462High· 8.9
1w ago

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service…

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service…

▾ Twilightopenmeter · openmeterEPSS 0.51%via NVD
CVE-2026-78472High· 8.6
1w ago

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.

▾ TwilightEPSS 0.45%via NVD
CVE-2026-76557Medium· 6.8
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Exp…

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Exp…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-76556Medium· 6.8
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by defa…

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by defa…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-16588Medium· 6.5
1w ago

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient pr…

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient pr…

▾ Sunlitwpdirectorykit · WP Directory KitEPSS 0.29%via NVD
CVE-2026-92221Medium· 4.7PoC
1w ago

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.p…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.35%via NVD
CVE-2026-87238High· 8.8
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with n…

▾ Twilightoracle · hyperion_financial_managementEPSS 0.55%via NVD
CVE-2026-87212High· 7.4
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Twilightoracle · hyperion_financial_managementEPSS 0.36%via NVD
CVE-2026-87207High· 7.2
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with …

▾ Twilightoracle · hyperion_financial_managementEPSS 0.57%via NVD
CVE-2026-87202High· 8.8
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with n…

▾ Twilightoracle · hyperion_financial_managementEPSS 0.55%via NVD
CVE-2026-87184Critical· 9.8
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.59%via NVD
CVE-2026-83210High· 8.8
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network…

▾ TwilightOracle Corporation · Siebel CRM DeploymentEPSS 0.52%via NVD
CWE-89 vulnerabilities (CVEs) — page 7 · VulnSea