Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-13527

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /prev…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13525

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file applicatio…

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13526

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This mani…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13520

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php o…

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13521

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functional…

Mitigation only
Fix from $1,950 2026-06-29
Joomcck CRITICAL 9.8
CVE-2026-49048

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request pa…

Fix: after 6.4.0
Fix from $2,300 2026-06-28
Unclassified MEDIUM 6.3
CVE-2026-13496

A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. …

Mitigation only
Fix from $1,600 2026-06-28
Unclassified MEDIUM 6.3
CVE-2026-13497

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.p…

Mitigation only
Fix from $1,600 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13498

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of …

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13488

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown funct…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13487

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13486

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13485

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Perform…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified MEDIUM 6.5
CVE-2026-13331

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.5
CVE-2026-13333

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter…

Mitigation only
Fix from $1,600 2026-06-27
Budibase CRITICAL 9.8
CVE-2026-54350

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the…

Fix: 3.39.12+
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-52785

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57662

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57663

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57667

Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57653

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57644

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57636

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57642

Contributor SQL Injection in Gallery <= 4.7.8 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57643

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.6
CVE-2026-57628

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.6
CVE-2026-57631

Administrator SQL Injection in Popup box <= 6.0.1 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56068

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

Mitigation only
Fix from $2,300 2026-06-26