Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.5
CVE-2026-40816

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm funct…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40817

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutra…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40818

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper ne…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40819

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40810

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40811

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralizatio…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40812

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions sn parameter due to impr…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40813

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to i…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40814

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _mb24confi_getTagAlarm functio…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-40815

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-9606

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such mani…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 6.3
CVE-2026-9607

A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Pe…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.3
CVE-2026-9584

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9573

A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/studen…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9574

A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/st…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9575

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admi…

Mitigation only
Fix from $1,950 2026-05-26
Twenty CRITICAL 9.9
CVE-2026-46624

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL …

Fix: 1.16.7+
Fix from $2,300 2026-05-26
Unclassified HIGH 8.5
CVE-2026-44706

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter API…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.6
CVE-2026-44680

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-orm/knex 6.6.14 and @mikro-orm…

Patch available
Fix from $1,950 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35221

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35222

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Cloud Pak For Data System Cyclops CRITICAL 9.8
CVE-2025-36220

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta…

Fix: 11.3.0.2+
Fix from $2,300 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9552

A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component S…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9551

A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.2
CVE-2026-42425

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements…

No fix yet
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9542

A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9544

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified MEDIUM 5.6
CVE-2026-48134

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who …

Mitigation only
Fix from $1,600 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9526

A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. Th…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9528

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Su…

Mitigation only
Fix from $1,950 2026-05-26