SQL Injection
Injection flaws in database query construction, with the reachable sink and the payload that proves it.
Published work on this topic
| 2026-09-25 | CVE-2026-19949 | CVE-2026-19949 Exploit: AIOWM Pre-Auth SQLi | PoC | |
| 2026-09-07 | CVE-2026-55634 | CVE-2026-55634: Pimcore - DataObject PHP Injection RCE | PoC | |
| 2026-08-29 | CVE-2026-16639 | CVE-2026-16639: Drupal i18n_sso Auth Bypass | PoC | |
| 2026-08-11 | CVE-2026-72899 | CVE-2026-72899: Metabase Unauthenticated SQL Injection | PoC | |
| 2026-08-11 | CVE-2026-72898 | CVE-2026-72898: Metabase SQL Injection - Admin Takeover | PoC | |
| 2026-08-04 | CVE-2026-42208 | CVE-2026-42208: LiteLLM Pre-Auth SQL Injection | PoC | |
| 2026-08-04 | CVE-2026-9082 | CVE-2026-9082: Drupal SQL Injection | PoC | |
| 2026-07-24 | CVE-2026-63030 | CVE-2026-63030: WordPress wp2shell Pre-Auth RCE | PoC |
Other topics
remote code execution38authentication bypass19wordpress14php13authorization bypass9java9path traversal9privilege escalation7code injection6denial of service6heap overflow6insecure deserialization5information disclosure5qemu5apache tomcat4go4node.js4python4cross-site scripting4buffer overflow3gitea3gitlab3javascript3
