Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.8
CVE-2026-39196

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition f…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 8.8
CVE-2026-36670

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows a…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.1
CVE-2019-25746

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database quer…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 8.2
CVE-2016-20071

The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to …

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 8.2
CVE-2016-20072

BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL que…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 8.2
CVE-2016-20073

Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 8.2
CVE-2016-20068

WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to …

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 8.2
CVE-2016-20069

WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to …

No fix yet
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.3
CVE-2026-12206

A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.3
CVE-2026-12188

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/c…

Mitigation only
Fix from $1,600 2026-06-14
Unclassified HIGH 7.6
CVE-2026-6428

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x befor…

Mitigation only
Fix from $1,950 2026-06-13
Unclassified HIGH 7.5
CVE-2026-9848

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.…

Mitigation only
Fix from $1,950 2026-06-13
Unclassified MEDIUM 6.3
CVE-2026-12131

A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \applic…

Mitigation only
Fix from $1,600 2026-06-12
MariaDB CRITICAL 9.1
CVE-2026-44172

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, …

Mitigation only
Fix from $2,300 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-41581

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This i…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.9
CVE-2026-48613

SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-45060

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified HIGH 8.8
CVE-2026-45418

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple …

Mitigation only
Fix from $1,950 2026-06-11
Unclassified CRITICAL 9.3
CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind …

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.3
CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. …

Mitigation only
Fix from $2,300 2026-06-11
Postgresql Anonymizer HIGH 7.5
CVE-2026-11945

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code…

Fix: 3.1.1+
Fix from $1,950 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-38581

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFor…

Mitigation only
Fix from $2,300 2026-06-11
Migration Assessment MEDIUM 6.5
CVE-2026-53474

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xls…

Fix: 0.13.5+
Fix from $1,600 2026-06-10
Ghidra HIGH 8.8
CVE-2026-52758

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries withou…

Fix: 12.1+
Fix from $1,950 2026-06-10
Ghidra HIGH 8.8
CVE-2026-49498

Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double…

Fix: 12.1+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-3018

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and inclu…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 8.6
CVE-2026-3326

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action avail…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 8.8
CVE-2026-50636

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), w…

Patch available
Fix from $1,950 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-8025

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform…

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-7486

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injectio…

Mitigation only
Fix from $2,300 2026-06-09