Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.2
CVE-2026-54348

Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75876

A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of t…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-47720

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString functio…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73392

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 7.1
CVE-2026-73345

Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 7.5
CVE-2026-66622

Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.5
CVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75778

A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of th…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75088

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75089

A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75086

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75087

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75079

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_sub…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75080

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-67854

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67917

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 8.4
CVE-2026-64657

Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts i…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.6
CVE-2026-65822

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactiv…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.3
CVE-2026-75014

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-74254

Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection iss…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-51346

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensit…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50769

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conf…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-20000

A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptio…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.4
CVE-2026-15623

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Clou…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19973

A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /vie…

Fix unknown
Fix from $4,000 2026-08-17