Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.8
CVE-2025-45868

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to ma…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.7
CVE-2026-58078

Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vu…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-15022

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-13754

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, a…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-13767

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-12395

The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authentic…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.5
CVE-2026-12753

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' p…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-12941

The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'orde…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.3
CVE-2026-15907

A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Exe…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-62361

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects t…

Patch available
Fix from $1,600 2026-07-15
Unclassified CRITICAL 10.0
CVE-2026-52887

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/…

Patch available
Fix from $2,300 2026-07-15
Unclassified HIGH 7.1
CVE-2026-50030

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlC…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-45535

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable …

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-45320

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed b…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-45417

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configura…

Patch available
Fix from $1,950 2026-07-15
Fineract HIGH 8.1
CVE-2026-56287

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Fineract HIGH 8.1
CVE-2026-57821

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Fineract HIGH 8.8
CVE-2026-35152

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-57831

Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulne…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-57832

Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthe…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.8
CVE-2026-15804

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, ther…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.6
CVE-2026-12512

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowi…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.9
CVE-2026-11851

Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models al…

Mitigation only
Fix from $1,600 2026-07-15
Coldfusion CRITICAL 9.1
CVE-2026-48324

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Mitigation only
Fix from $2,300 2026-07-14
Commerce HIGH 7.2
CVE-2026-47992EPSS 20%

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result…

Fix: 1.21.0+
Fix from $1,950 2026-07-14
Symfony HIGH 7.3
CVE-2026-45073

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAda…

Fix: 5.4.52 / 6.4.40+
Fix from $1,950 2026-07-14
Sql Server 2016 HIGH 8.8
CVE-2026-47295

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $1,950 2026-07-14
Sql Server 2016 HIGH 7.5
CVE-2026-47296

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $1,950 2026-07-14
Unclassified HIGH 7.3
CVE-2026-15703

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/u…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 8.3
CVE-2026-15736

Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifi…

Mitigation only
Fix from $1,950 2026-07-14