Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Rucio HIGH 8.8
CVE-2026-29080

A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend …

Fix: 35.8.5 / 38.5.5+
Fix from $1,950 2026-05-06
Unclassified HIGH 7.5
CVE-2026-1719

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient esca…

Mitigation only
Fix from $1,950 2026-05-06
Unclassified CRITICAL 9.3
CVE-2026-40331

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified HIGH 8.1
CVE-2026-44331

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attac…

Patch available
Fix from $1,950 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40329

Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc compone…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40330

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7…

Mitigation only
Fix from $2,300 2026-05-05
Sqlbot HIGH 8.8
CVE-2026-33324

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vul…

Fix: 1.7.1+
Fix from $1,950 2026-05-05
Kestra CRITICAL 9.8
CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly conc…

Fix: 1.0.35 / 1.3.7+
Fix from $2,300 2026-05-05
Unclassified HIGH 7.5
CVE-2026-4304

The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3.4.11 …

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2026-3359

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' param…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40797

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQ…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified MEDIUM 6.3
CVE-2026-7822

A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The mani…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified HIGH 7.5
CVE-2026-3456

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attribute…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 8.7
CVE-2026-35228

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is af…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2026-5100

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified MEDIUM 6.3
CVE-2026-7783

A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::applySortQuery of the file applic…

Mitigation only
Fix from $1,600 2026-05-05
N8n HIGH 8.8
CVE-2026-42237

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the…

Fix: 1.123.32 / 2.17.4+
Fix from $1,950 2026-05-04
N8n HIGH 8.8
CVE-2026-42229

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:…

Fix: 1.123.32 / 2.17.4+
Fix from $1,950 2026-05-04
N8n CRITICAL 9.8
CVE-2026-42233

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select opera…

Fix: 1.123.32 / 2.17.4+
Fix from $2,300 2026-05-04
Cosmos CRITICAL 9.6
CVE-2026-42087

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before …

Fix: 7.0.0+
Fix from $2,300 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7745

A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This …

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7746

A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /produ…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7744

A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipul…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7741

A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7742

A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Execu…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7743

A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdet…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7731

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file ge…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7727

A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineG…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7716

A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /inde…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7699

A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file Str…

Mitigation only
Fix from $1,600 2026-05-03