Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.8
CVE-2026-31069

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter na…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 7.5
CVE-2026-8912

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 8.2
CVE-2026-8726

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrar…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 8.2
CVE-2026-8827

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method …

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 8.1
CVE-2026-8851

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated u…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 8.6
CVE-2026-6379

The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 7.3
CVE-2026-8785

A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of t…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 7.3
CVE-2026-8771

A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 8.2
CVE-2018-25338

Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information usin…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 8.2
CVE-2018-25339

Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 8.2
CVE-2018-25330

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious c…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 8.2
CVE-2018-25333

Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 7.1
CVE-2018-25319

Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecti…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 7.3
CVE-2026-8734

A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the compon…

Mitigation only
Fix from $1,950 2026-05-17
Dataease HIGH 7.2
CVE-2026-8724

A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the c…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 7.1
CVE-2021-47980

Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 8.2
CVE-2021-47954

LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 8.2
CVE-2021-47956

EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting S…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 8.2
CVE-2020-37242

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inje…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 8.2
CVE-2020-37243

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute ar…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 8.2
CVE-2020-37244

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injectin…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 7.5
CVE-2026-46359

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified CRITICAL 9.8
CVE-2026-46364

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha()…

Patch available
Fix from $2,300 2026-05-15
Unclassified HIGH 8.7
CVE-2026-45800

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an authenticated S…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 8.2
CVE-2021-47966

PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows u…

No fix yet
Fix from $1,950 2026-05-15
Unclassified HIGH 7.1
CVE-2026-42847

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) vulnerability in ClipBucket, …

Mitigation only
Fix from $1,950 2026-05-14
Strapi HIGH 7.2
CVE-2026-22599

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a d…

Fix: 4.26.1 / 5.33.2+
Fix from $1,950 2026-05-14
PostgreSQL HIGH 7.2
CVE-2026-6476

SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The a…

Fix: 17.10 / 18.4+
Fix from $1,950 2026-05-14
PostgreSQL HIGH 8.8
CVE-2026-6637

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user runni…

Fix: 14.23 / 15.18+
Fix from $1,950 2026-05-14
PostgreSQL HIGH 8.8
CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL…

Fix: 16.14 / 17.10+
Fix from $1,950 2026-05-14