Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.8
CVE-2025-11024

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified MEDIUM 6.5
CVE-2026-6225

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection vi…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified HIGH 7.1
CVE-2026-46445

SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.

Patch available
Fix from $1,950 2026-05-14
Unclassified HIGH 7.1
CVE-2026-46446

SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@…

Patch available
Fix from $1,950 2026-05-14
Unclassified MEDIUM 6.5
CVE-2026-5486

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addon…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified HIGH 8.1
CVE-2026-29206

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging …

Mitigation only
Fix from $1,950 2026-05-13
Erpnext HIGH 7.5
CVE-2026-44446

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection t…

Fix: 15.104.3 / 16.14.0+
Fix from $1,950 2026-05-13
Erpnext HIGH 7.5
CVE-2026-44447

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through special…

Fix: 16.9.0+
Fix from $1,950 2026-05-13
Misp MEDIUM 5.3
CVE-2026-44381

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-contr…

Fix: 2.5.37+
Fix from $1,600 2026-05-13
Unclassified HIGH 8.7
CVE-2026-44418

EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view pass…

Patch available
Fix from $1,950 2026-05-13
Unclassified HIGH 7.2
CVE-2026-39358

CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorti…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified HIGH 8.8
CVE-2026-42550

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL stateme…

Mitigation only
Fix from $1,950 2026-05-13
Ckan CRITICAL 9.8
CVE-2026-42031

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor…

Fix: 2.10.10 / 2.11.5+
Fix from $2,300 2026-05-13
Unclassified MEDIUM 6.1
CVE-2026-0242

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product d…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified HIGH 7.1
CVE-2020-37226

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by inje…

No fix yet
Fix from $1,950 2026-05-13
Unclassified HIGH 8.2
CVE-2020-37218

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQ…

No fix yet
Fix from $1,950 2026-05-13
Unclassified HIGH 7.1
CVE-2020-37224

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by inje…

No fix yet
Fix from $1,950 2026-05-13
Unclassified MEDIUM 6.5
CVE-2026-4608

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all vers…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.5
CVE-2026-37429

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vuln…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.5
CVE-2026-37428

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vuln…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified HIGH 7.5
CVE-2026-4798

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and includi…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified HIGH 7.5
CVE-2026-6929

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sort…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified MEDIUM 6.5
CVE-2026-7619

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Inject…

Mitigation only
Fix from $1,600 2026-05-13
Unclassified HIGH 7.2
CVE-2026-6888

Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific i…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified HIGH 7.5
CVE-2026-1250

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all v…

Mitigation only
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44864

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44860

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44861

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44862

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.2
CVE-2026-44863

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12