Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.5
CVE-2026-28168

Subscriber SQL Injection in CubeWP <= 1.1.30 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.5
CVE-2026-28156

Subscriber SQL Injection in Do Lasso <= 358 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-28001

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.5
CVE-2026-28002

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. …

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-28142

Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.5
CVE-2026-27538

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-15741

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attack…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-11840

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL inj…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-73331

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.7
CVE-2026-73332

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers t…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.0
CVE-2026-72807

SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks funct…

No fix yet
Fix from $4,900 2026-08-12
Ash Framework HIGH 7.4
CVE-2026-67579

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged …

No fix yet
Fix from $4,900 2026-08-12
I CRITICAL 9.8
CVE-2026-17111

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.6
CVE-2026-73300

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.8
CVE-2026-44741

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 7.8
CVE-2026-17418

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elemen…

Fix: after 7.6
Fix from $4,900 2026-08-12
I MEDIUM 6.5
CVE-2026-17419

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used…

Fix: after 7.6
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.3
CVE-2026-66659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.6
CVE-2026-18474

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL inje…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-18230

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its aut…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-18057

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing u…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-16977

The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQ…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-13613

The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-73211

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.0
CVE-2026-48381

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2016-20097

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2022-50997

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated rem…

No fix yet
Fix from $4,900 2026-08-11
Entra Connect HIGH 7.8
CVE-2026-65673

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-73069

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MOD…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-46670

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat…

No fix yet
Fix from $5,750 2026-08-11