Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Focalpoint HIGH 8.2
CVE-2017-20263

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu…

No fix yet
Fix from $1,950 2026-06-19
Sponsor Wall HIGH 7.1
CVE-2017-20264

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by …

No fix yet
Fix from $1,950 2026-06-19
Flip Wall HIGH 7.1
CVE-2017-20265

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj…

No fix yet
Fix from $1,950 2026-06-19
Standard Pro Movie Database HIGH 8.2
CVE-2017-20266

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inject…

No fix yet
Fix from $1,950 2026-06-19
Calendar Planner HIGH 8.2
CVE-2017-20267

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through…

No fix yet
Fix from $1,950 2026-06-19
Jb Visa HIGH 8.2
CVE-2017-20255

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injec…

No fix yet
Fix from $1,950 2026-06-19
Survey Force Deluxe HIGH 8.2
CVE-2017-20256

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by in…

No fix yet
Fix from $1,950 2026-06-19
Quiz Deluxe HIGH 8.2
CVE-2017-20257

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands t…

No fix yet
Fix from $1,950 2026-06-19
Responsive Portfolio HIGH 8.2
CVE-2017-20258

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S…

No fix yet
Fix from $1,950 2026-06-19
Osdownloads HIGH 8.2
CVE-2017-20259

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting …

No fix yet
Fix from $1,950 2026-06-19
Price Alert HIGH 8.2
CVE-2017-20260

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by…

No fix yet
Fix from $1,950 2026-06-19
Bargain Product Vm3 HIGH 8.2
CVE-2017-20261

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL quer…

No fix yet
Fix from $1,950 2026-06-19
Ajax Quiz HIGH 8.2
CVE-2017-20262

Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj…

No fix yet
Fix from $1,950 2026-06-19
My Projects HIGH 8.2
CVE-2017-20253

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i…

No fix yet
Fix from $1,950 2026-06-19
User Bench HIGH 8.2
CVE-2017-20254

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by in…

No fix yet
Fix from $1,950 2026-06-19
Nextgen Editor HIGH 8.2
CVE-2017-20252

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through t…

No fix yet
Fix from $1,950 2026-06-19
Pgadmin 4 HIGH 8.8
CVE-2026-12050

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was inter…

Fix: 9.16+
Fix from $1,950 2026-06-19
Pgadmin 4 HIGH 8.8
CVE-2026-12044

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The…

Fix: 9.16+
Fix from $1,950 2026-06-19
Pgadmin 4 HIGH 8.8
CVE-2026-12045

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute …

Fix: 9.16+
Fix from $1,950 2026-06-19
Unclassified HIGH 8.5
CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Bl…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) conta…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified HIGH 8.6
CVE-2026-54222

UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying data…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 8.6
CVE-2026-40455

An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient san…

Patch available
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-55740

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulner…

Mitigation only
Fix from $2,300 2026-06-18
Powerflex Manager MEDIUM 5.7
CVE-2026-35068

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection…

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,600 2026-06-17
Powerflex Manager HIGH 8.0
CVE-2026-35069

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection…

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injectio…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified HIGH 8.5
CVE-2026-54813

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Inje…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-54815

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerc…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified HIGH 8.5
CVE-2026-54818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL …

Mitigation only
Fix from $1,950 2026-06-17