Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified MEDIUM 6.3
CVE-2026-19972

A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewpatient.php. Such man…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-74251

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specificat…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.2
CVE-2026-2497

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all version…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-9767

The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19934

A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manip…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-18653

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrato…

Fix unknown
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-15963

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-16079

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and i…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.3
CVE-2026-19926

A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-ga…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19923

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.3
CVE-2026-19919

A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19920

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulatio…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19921

A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /h…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19917

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. …

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.3
CVE-2026-19905

A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx…

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 7.3
CVE-2026-19899

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.3
CVE-2026-19894

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewmedicine.php. Pe…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-12248

The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all versions up to, and including, 4.9.5…

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.1
CVE-2026-16007

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-18387

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'tag_query' parameter…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-16586

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via Mul…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-15993

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}'…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-15453

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-16080

The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and …

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.5
CVE-2026-15162

The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-s…

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 8.6
CVE-2026-71571

Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.2
CVE-2026-67365

Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (…

No fix yet
Fix from $5,750 2026-08-14
Unclassified MEDIUM 5.4
CVE-2026-17227

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of …

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.0
CVE-2026-18403

LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that cop…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.6
CVE-2026-73850

Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.ph…

No fix yet
Fix from $4,900 2026-08-14