Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Pgx CRITICAL 9.8
CVE-2026-41889

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar…

Fix: 5.9.2+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-37431

Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.…

Mitigation only
Fix from $2,300 2026-05-08
Praisonai MEDIUM 6.3
CVE-2026-44337

PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL-backed knowledge-store imple…

Fix: 4.6.34+
Fix from $1,600 2026-05-08
Praisonaiagents HIGH 8.1
CVE-2026-41496

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input v…

Fix: 1.6.9 / 4.6.9+
Fix from $1,950 2026-05-08
Unclassified HIGH 8.6
CVE-2026-4935

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, …

Mitigation only
Fix from $1,950 2026-05-08
Unclassified CRITICAL 9.8
CVE-2023-46453

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified HIGH 7.3
CVE-2024-33288

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

No fix yet
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.3
CVE-2024-33722

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8133

A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file d…

Patch available
Fix from $1,950 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8132

A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8129

A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Execu…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8130

A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipu…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8131

A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The …

Mitigation only
Fix from $1,950 2026-05-08
Litellm CRITICAL 9.8
CVE-2026-42208 KEVEPSS 89%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query…

Fix: 1.83.7+
Fix from $2,300 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8126

A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulatio…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 7.3
CVE-2026-8128

A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Perf…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.3
CVE-2026-8125

A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipu…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.3
CVE-2026-8114

A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of t…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 6.3
CVE-2026-8097

A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipul…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified HIGH 7.3
CVE-2026-8098

A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. S…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 7.3
CVE-2026-8083

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_u…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 7.1
CVE-2026-44349

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_findallpaginated.go:1484 splits th…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 8.3
CVE-2026-41422

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 8.3
CVE-2026-41490

Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior …

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 7.6
CVE-2025-68060

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. …

Mitigation only
Fix from $1,950 2026-05-07
Nocobase HIGH 7.2
CVE-2026-41641

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQ…

Fix: 2.0.39+
Fix from $1,950 2026-05-07
Unclassified HIGH 7.5
CVE-2026-4348

The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in al…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 8.8
CVE-2026-41143

YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/…

Mitigation only
Fix from $1,950 2026-05-07
Nocobase HIGH 8.8
CVE-2026-41640

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryPa…

Fix: 2.0.39+
Fix from $1,950 2026-05-07
Rucio HIGH 8.8
CVE-2026-29090

### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.crea…

Fix: 35.8.5 / 38.5.5+
Fix from $1,950 2026-05-06