CVEs classified under CWE-943, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-40141 — CVSS 9.9 (critical): A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to…
CVE-2024-4872 — CVSS 9.9 (critical): A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated…
CVE-2026-41274 — CVSS 9.8 (critical): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node…
CVE-2026-40351 — CVSS 9.8 (critical): FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion…
CVE-2026-32248 — CVSS 9.8 (critical): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38…
CVE-2026-29793 — CVSS 9.8 (critical): Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42…
CVE-2026-45689 — CVSS 9.1 (critical): Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5…
CVE-2026-45688 — CVSS 9.1 (critical): Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5…
CVE-2026-41328 — CVSS 9.1 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an…
CVE-2026-41327 — CVSS 9.1 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an…
CVE-2026-76316 — CVSS 8.8 (high): In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port…
CVE-2026-40352 — CVSS 8.8 (high): FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An…
CVE-2018-7829 — CVSS 8.8 (high): An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra…
CVE-2017-12904 — CVSS 8.8 (high): Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows…
CVE-2026-63637 — CVSS 8.6 (high): Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp…
CVE-2026-47835 — CVSS 8.6 (high): In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and…
CVE-2025-24787 — CVSS 8.6 (high): WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter injection in database…
CVE-2026-73618 — CVSS 8.3 (high): Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied…
CVE-2026-33980 — CVSS 8.3 (high): Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure…
CVE-2026-46591 — CVSS 8.2 (high): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer…
CVE-2026-76331 — CVSS 8.1 (high): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could…
CVE-2025-60357 — CVSS 8.1 (high): AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
CVE-2026-32247 — CVSS 8.1 (high): Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher…
CVE-2026-28211 — CVSS 7.8 (high): The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions…
CVE-2026-22558 — CVSS 7.7 (high): An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access…
CVE-2026-76254 — CVSS 7.5 (high): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to…
CVE-2026-44840 — CVSS 7.5 (high): Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is…
CVE-2026-30941 — CVSS 7.5 (high): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1…
CVE-2026-10698 — CVSS 7.2 (high): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This…
CVE-2026-77070: n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate…
CVE-2026-73617 — CVSS 7.1 (high): Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are…
CVE-2026-53674 — CVSS 7.1 (high): BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility…
CVE-2026-42156: Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to…
CVE-2026-48121 — CVSS 6.7 (medium): @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions…
CVE-2026-76363 — CVSS 6.5 (medium): In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL)…
CVE-2026-40102 — CVSS 6.5 (medium): Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment…
CVE-2026-42316 — CVSS 6.5 (medium): kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3…
CVE-2026-25591 — CVSS 6.5 (medium): New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10…
CVE-2025-36442 — CVSS 6.5 (medium): IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service…
CVE-2025-36366 — CVSS 6.5 (medium): IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that…
CVE-2025-42884 — CVSS 6.5 (medium): SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI…
CVE-2021-1349 — CVSS 6.5 (medium): A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to…
CVE-2026-76349 — CVSS 6.4 (medium): In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running…
CVE-2026-76329 — CVSS 6.4 (medium): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin"…
CVE-2026-76327 — CVSS 6.4 (medium): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and…
CVE-2026-8649 — CVSS 6.4 (medium): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This…
CVE-2025-36353 — CVSS 6.2 (medium): IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a…
CVE-2025-36185 — CVSS 6.2 (medium): IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of…
CVE-2026-76320 — CVSS 5.9 (medium): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run…
CVE-2026-41696 — CVSS 5.9 (medium): Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the…