Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.3
CVE-2026-54760

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation,…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.5
CVE-2026-59834

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concate…

Patch available
Fix from $1,950 2026-07-09
Unclassified HIGH 7.7
CVE-2026-55208

Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin p…

Patch available
Fix from $1,950 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15190

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Perform…

Mitigation only
Fix from $1,950 2026-07-09
Acymailing HIGH 7.5
CVE-2026-56292

Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joom…

Fix: 10.11.1+
Fix from $1,950 2026-07-09
Unclassified HIGH 8.6
CVE-2026-50644

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands int…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticare…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-13011

The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15135

A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15137

A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\Vie…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15134

A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of …

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-39178

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the al…

Patch available
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-39179

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in t…

Patch available
Fix from $1,600 2026-07-08
Api Connect CRITICAL 9.8
CVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…

Fix: 10.0.8.10 / 12.1.1.0+
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.6
CVE-2026-15062

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 8.8
CVE-2026-15067

Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data sourc…

Mitigation only
Fix from $1,950 2026-07-08
N8n HIGH 8.8
CVE-2026-59257

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery op…

Fix: 1.123.61 / 2.27.4+
Fix from $1,950 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-8307

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Inje…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 7.5
CVE-2026-6854

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all ve…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-6230

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.…

Patch available
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-9700

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due t…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.7
CVE-2026-55635

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter va…

Patch available
Fix from $1,950 2026-07-07
Unclassified MEDIUM 6.9
CVE-2026-33734

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Mass…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified HIGH 8.1
CVE-2026-14471

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.5
CVE-2026-14809

Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL com…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14797

A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-v…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14798

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartmen…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14799

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishl…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14795

A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14796

A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.ph…

Mitigation only
Fix from $1,600 2026-07-06