Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.8
CVE-2026-52472

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

No fix yet
Fix from $2,300 2026-07-21
Security Center HIGH 7.1
CVE-2026-64880

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized que…

Fix available
Fix from $1,950 2026-07-21
Unclassified HIGH 8.7
CVE-2026-55082

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed a…

Patch available
Fix from $1,950 2026-07-21
Unclassified HIGH 8.8
CVE-2026-55084

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was ident…

Patch available
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2016-20096

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute ar…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 8.6
CVE-2026-15829

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of…

Patch available
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.3
CVE-2026-16449

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem…

No fix yet
Fix from $1,600 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-1617

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspo…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 7.5
CVE-2026-8082

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce or…

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.3
CVE-2026-16334

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 8.2
CVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…

Patch available
Fix from $1,950 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16252

A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.3
CVE-2026-57309

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in…

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16244

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.6
CVE-2026-11349

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16228

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php.…

No fix yet
Fix from $1,950 2026-07-19
Unclassified HIGH 7.3
CVE-2026-16227

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edi…

No fix yet
Fix from $1,950 2026-07-19
Unclassified HIGH 7.3
CVE-2026-16152

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Perfo…

No fix yet
Fix from $1,950 2026-07-18
Unclassified HIGH 7.3
CVE-2026-16154

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functional…

No fix yet
Fix from $1,950 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16131

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. …

No fix yet
Fix from $1,600 2026-07-18
Unclassified CRITICAL 9.8
CVE-2026-52348

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

No fix yet
Fix from $2,300 2026-07-17
WordPress MEDIUM 5.9
CVE-2026-60137 KEVEPSS 73%

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

Fix: 6.8.6 / 6.9.5+
Fix from $1,600 2026-07-17
Unclassified HIGH 8.7
CVE-2026-44739

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/Custom…

Patch available
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.8
CVE-2026-12283

Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.3
CVE-2026-9586

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-8297

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laborato…

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 7.3
CVE-2026-16014

A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16009

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php…

No fix yet
Fix from $1,600 2026-07-17
Openremote HIGH 8.8
CVE-2026-62238

OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL qu…

Fix: 1.26.0+
Fix from $1,950 2026-07-17