Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified MEDIUM 6.5
CVE-2026-44204

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /ass…

Patch available
Fix from $1,600 2026-05-12
Fortindr HIGH 8.8
CVE-2026-25088

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, Forti…

Fix: 7.4.10 / 7.6.3+
Fix from $1,950 2026-05-12
Fortimail HIGH 7.2
CVE-2025-53681

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7…

Fix: 7.2.9 / 7.4.6+
Fix from $1,950 2026-05-12
Pandora Fms CRITICAL 9.8
CVE-2026-34187

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affec…

Fix: 777.17 / 802+
Fix from $2,300 2026-05-12
Endpoint Manager HIGH 8.8
CVE-2026-8111

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exe…

Fix: after 2022
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-43937

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttri…

Mitigation only
Fix from $1,950 2026-05-12
Postgrex HIGH 7.8
CVE-2026-32687

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifica…

Fix: 0.22.0+
Fix from $1,950 2026-05-12
Dovecot CRITICAL 9.1
CVE-2026-27851

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe…

Fix: 2.4.4 / 3.1.5+
Fix from $2,300 2026-05-12
Unclassified HIGH 7.7
CVE-2026-45218

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL …

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.5
CVE-2026-42741

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Ed…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.5
CVE-2026-42742

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite a…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.5
CVE-2026-45211

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce wo…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.6
CVE-2026-45213

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQ…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.5
CVE-2026-45214

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addon…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.0
CVE-2026-41125

A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified CRITICAL 9.8
CVE-2025-6577

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. …

Mitigation only
Fix from $2,300 2026-05-12
Unclassified MEDIUM 6.5
CVE-2026-5028

The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-artic…

No fix yet
Fix from $1,600 2026-05-12
Unclassified HIGH 7.5
CVE-2026-2993

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insu…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.6
CVE-2026-34260

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL sta…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 7.3
CVE-2026-36962

SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative …

Mitigation only
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.8
CVE-2026-38567

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries witho…

Mitigation only
Fix from $2,300 2026-05-11
Pgadmin 4 HIGH 8.8
CVE-2026-7815

SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup…

Fix: 9.15+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.0
CVE-2026-6093

Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issu…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 8.2
CVE-2021-47941

WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries…

No fix yet
Fix from $1,950 2026-05-10
Unclassified HIGH 8.2
CVE-2021-47930

Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attacker…

No fix yet
Fix from $1,950 2026-05-10
Unclassified HIGH 8.2
CVE-2021-47928

Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by …

No fix yet
Fix from $1,950 2026-05-10
Unclassified MEDIUM 6.3
CVE-2026-8231

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The m…

Mitigation only
Fix from $1,600 2026-05-10
PHP CRITICAL 9.8
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
Unclassified HIGH 7.0
CVE-2026-8207

Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/Gib…

Mitigation only
Fix from $1,950 2026-05-09
Unclassified CRITICAL 10.0
CVE-2026-42287

Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attack…

Mitigation only
Fix from $2,300 2026-05-08