Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.1
CVE-2018-25346

WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database querie…

No fix yet
Fix from $1,950 2026-05-23
Unclassified HIGH 7.1
CVE-2018-25347

WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries …

No fix yet
Fix from $1,950 2026-05-23
Unclassified HIGH 8.2
CVE-2018-25348

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inje…

No fix yet
Fix from $1,950 2026-05-23
Unclassified HIGH 8.2
CVE-2018-25340

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code…

No fix yet
Fix from $1,950 2026-05-23
Unclassified HIGH 8.2
CVE-2018-25341

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code…

No fix yet
Fix from $1,950 2026-05-23
Unclassified MEDIUM 6.3
CVE-2026-9305

A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file…

Mitigation only
Fix from $1,600 2026-05-23
Unclassified HIGH 8.8
CVE-2026-41075

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injectio…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified HIGH 8.7
CVE-2026-25606

A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for …

Mitigation only
Fix from $1,950 2026-05-22
Unclassified HIGH 7.5
CVE-2026-4834

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This i…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified HIGH 7.1
CVE-2026-48233

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET parameter is concatenated into …

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48234

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort and dir GET parameters are con…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 8.2
CVE-2026-48235

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude, an…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48236

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, t…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48237

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are con…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48238

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET parameter is concatenated into the WH…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48239

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into the …

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48240

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are con…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48231

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters (tablename, indexname, sortby…

Patch available
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-48232

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GET parameter is concatenated i…

Patch available
Fix from $1,950 2026-05-21
Unclassified CRITICAL 9.3
CVE-2026-39531

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind …

Mitigation only
Fix from $2,300 2026-05-21
Unclassified HIGH 8.8
CVE-2026-44047

An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorize…

Mitigation only
Fix from $1,950 2026-05-21
Drupal CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This …

Fix: 10.4.10 / 10.5.10+
Fix from $2,300 2026-05-20
Infoscale Operations Manager MEDIUM 6.5
CVE-2026-44923

SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.

Fix: 9.1.3+
Fix from $1,600 2026-05-20
Unclassified HIGH 7.6
CVE-2026-42383

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Bl…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified CRITICAL 9.3
CVE-2026-9059

NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.3
CVE-2026-9065

SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'p…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified HIGH 7.5
CVE-2026-9003

E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQ…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified HIGH 7.5
CVE-2026-9010

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and incl…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.5
CVE-2026-8685

The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified HIGH 7.5
CVE-2026-3985

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parame…

Mitigation only
Fix from $1,950 2026-05-20