Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.2
CVE-2018-25398

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25399

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25400

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25401

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25402

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25389

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25390

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 7.1
CVE-2018-25392

MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25394

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25395

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25382

Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code throug…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25385

E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 8.2
CVE-2018-25386

HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL …

No fix yet
Fix from $1,950 2026-05-29
Freepbx HIGH 8.8
CVE-2026-44238

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST para…

Fix: 16.0.50 / 17.0.11+
Fix from $1,950 2026-05-29
Unclassified HIGH 7.1
CVE-2026-4776

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query paramet…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-45288

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-suppl…

Patch available
Fix from $2,300 2026-05-28
Unclassified MEDIUM 6.5
CVE-2026-7048

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' pa…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 7.5
CVE-2026-7797

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection v…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.7
CVE-2026-44886

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnera…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-44635

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metachara…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-44521

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.3
CVE-2026-38808

SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.5
CVE-2026-38930

OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is explo…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 8.5
CVE-2026-49046

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Bli…

Mitigation only
Fix from $1,950 2026-05-27
Anonymizer HIGH 8.8
CVE-2026-9617

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside …

No fix yet
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42761

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42747

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-buil…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42755

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allow…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42740

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Inj…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42727

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer…

Mitigation only
Fix from $2,300 2026-05-27