VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

810 CVEsRSS

CVE-2026-83208High· 8.8
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via …

▾ TwilightOracle Corporation · Siebel CRM DeploymentEPSS 0.52%via NVD
CVE-2026-32599Medium· 5.3
1w ago

Netmaker makes networks with WireGuard

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an au…

▾ Sunlitgravitl · netmakerEPSS 0.36%via NVD
CVE-2026-81567High· 8.7
1w ago

Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g

Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer rec…

▾ Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.39%via NVD
CVE-2026-81895High· 7.2
1w ago

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

▾ Twilightconcretecms · concrete_cmsEPSS 0.51%via NVD
CVE-2026-81894Medium· 5.4⚖ disputed
1w ago

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2024-58385Critical· 9.8PoC
1w ago

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…

▾ AbyssalYonyou · U8 CRMEPSS 0.38%via NVD
CVE-2026-91848High· 7.3PoC
1w ago

A vulnerability was identified in WuzhiCMS up to 4.1.0

A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads t…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-79303Critical· 9.9PoC
1w ago

kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection

kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.

▾ AbyssalEPSS 0.43%via NVD
CVE-2026-91004High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack c…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-16593Medium· 6.8
1w ago

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL in…

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL in…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-90879High· 7.3PoC
1w ago

A vulnerability was identified in zyx0814 FilePress up to 3.0.1

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql inj…

▾ Midnightzyx0814 · FilePressEPSS 0.43%via NVD
CVE-2026-90877High· 7.3PoC
1w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injec…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90876High· 7.3PoC
1w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql inject…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90855High· 7.3PoC
1w ago

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be init…

▾ MidnightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVE-2026-90854High· 7.3
1w ago

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injec…

▾ TwilightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVE-2026-90849High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.43%via NVD
CVE-2026-90846High· 7.3PoC
1w ago

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90844High· 7.3PoC
1w ago

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90841High· 7.3PoC
1w ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.43%via NVD
CVE-2026-61667Critical· 9.9
1w ago

DIRAC is an interware, meaning a software framework for distributed computing

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled data…

▾ MidnightDIRACGrid · DIRACEPSS 1.2%via NVD
CVE-2026-82028High· 8.8
1w ago

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that…

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that…

▾ Twilightabsmach · magistralaEPSS 0.60%via NVD
CVE-2026-90805High· 7.3PoC
1w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd ca…

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.43%via NVD
CVE-2026-90796Medium· 6.3PoC
1w ago

A vulnerability was identified in itsourcecode Leave Management System 1.0

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-76461Critical· 9.8CISA KEV0dayPoC
1w ago

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

▾ Hadalcisco · asyncosEPSS 28%via NVD
CVE-2026-90700Medium· 6.3PoC
1w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86460Critical· 9.8
1w ago

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. U…

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. U…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-neo4jEPSS 0.60%via NVD
CVE-2026-90708High· 7.3PoC
1w ago

A weakness has been identified in Yot CMS up to 3.3.1

A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injectio…

▾ MidnightYot · CMSEPSS 0.41%via NVD
CVE-2026-89180High· 7.5
1w ago

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

▾ TwilightThinking Software Technology · EFenceEPSS 0.56%via NVD
CVE-2026-82232Critical· 9.8
1w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.60%via NVD
CVE-2026-77051Critical· 9.8
1w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.60%via NVD
CWE-89 vulnerabilities (CVEs) — page 8 · VulnSea