Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-15490

A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknow…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified HIGH 7.3
CVE-2026-15489

A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unkno…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified HIGH 7.3
CVE-2026-15482

A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15477

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/s…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified MEDIUM 6.3
CVE-2026-15478

A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php…

Mitigation only
Fix from $1,600 2026-07-12
Unclassified CRITICAL 9.8
CVE-2026-60090

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() …

Patch available
Fix from $2,300 2026-07-11
Unclassified HIGH 7.5
CVE-2026-4661

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname…

No fix yet
Fix from $1,950 2026-07-11
Unclassified HIGH 7.5
CVE-2026-15335

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and inclu…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-15073

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-15072

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-13262

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val'…

Mitigation only
Fix from $1,600 2026-07-11
Geolocation Field MEDIUM 6.5
CVE-2026-13242

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. …

Fix: 3.15.0+
Fix from $1,600 2026-07-10
Location Selector HIGH 7.4
CVE-2026-15081

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. …

Fix: 1.3+
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-57230

OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy ena…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 7.6
CVE-2026-55405

LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-11321

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, wi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-5801

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt…

Mitigation only
Fix from $2,300 2026-07-10
Dify HIGH 8.8
CVE-2026-61461

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by s…

Fix: 1.16.0+
Fix from $1,950 2026-07-10
Coturn HIGH 7.2
CVE-2026-53448

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters direc…

Fix: 4.12.0+
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-2397

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.2
CVE-2026-58492

grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a…

Patch available
Fix from $2,300 2026-07-10
Powerflex Manager HIGH 7.7
CVE-2026-56689

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') …

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,950 2026-07-10
Powerflex Manager HIGH 8.5
CVE-2026-56690

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') …

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-13010

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortco…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-15104

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-15300

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, …

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.9
CVE-2026-15289

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in al…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-15290

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-15287

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all ve…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.7
CVE-2026-50180

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_valid…

Patch available
Fix from $1,950 2026-07-10