Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unifi Talk Application CRITICAL 9.9
CVE-2026-50747

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi …

Fix: 5.2.2+
Fix from $2,300 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

No fix yet
Fix from $1,950 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.3
CVE-2026-57683

Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.3
CVE-2026-57679

Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.

No fix yet
Fix from $2,300 2026-07-02
Unclassified HIGH 8.5
CVE-2025-69094

Subscriber SQL Injection in Unicamp <= 2.2.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-14029

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.5
CVE-2026-8441

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action i…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-52186

SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc c…

Mitigation only
Fix from $2,300 2026-07-01
Cargo CRITICAL 9.8
CVE-2026-14363

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…

Fix: 3.9.1+
Fix from $2,300 2026-07-01
Cargo CRITICAL 9.8
CVE-2026-58521

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte…

Fix: 3.9.1+
Fix from $2,300 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-51946

SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive in…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34101

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extensio…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34102

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where i…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34103

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extensio…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34104

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34105

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, ext…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = …

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34100

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, t…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-13454

The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-11823

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-12110

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'ta…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-12090

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wp…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.3
CVE-2026-55721

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie valu…

Mitigation only
Fix from $2,300 2026-06-30
App Connect Enterprise MEDIUM 5.5
CVE-2026-3602

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is v…

Fix: 12.0.12.27 / 13.0.8.0+
Fix from $1,600 2026-06-30
Unclassified HIGH 7.6
CVE-2026-58376

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary …

Patch available
Fix from $1,950 2026-06-30
Gravitino MEDIUM 5.4
CVE-2025-53648

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to…

Fix: 1.0.0+
Fix from $1,600 2026-06-30