Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.8
CVE-2025-67403

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-67404

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67405

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67406

https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). T…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67407

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67408

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69942

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69943

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Mitigation only
Fix from $2,300 2026-07-29
Unclassified HIGH 7.3
CVE-2025-69944

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-65340

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.8
CVE-2026-5490

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-8339

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authentica…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-51992

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries …

Mitigation only
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65890

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Unclassified MEDIUM 5.1
CVE-2026-33385

A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.1
CVE-2026-12895

SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interp…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO …

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, …

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.1
CVE-2026-63231

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-f…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63232

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcem…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63233

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall an…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63234

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessmen…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-54658

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive …

Mitigation only
Fix from $2,300 2026-07-28
Unclassified MEDIUM 6.3
CVE-2026-11391

Tanium addressed a SQL injection vulnerability in Patch.

No fix yet
Fix from $1,600 2026-07-28
Sterling B2b Integrator HIGH 8.1
CVE-2026-7769

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0…

Fix: after 6.2.2.0_1
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.0
CVE-2026-50736

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads…

No fix yet
Fix from $2,300 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-15304

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4.…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-14785

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-16462

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL comm…

No fix yet
Fix from $2,300 2026-07-28