Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-7695

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown func…

Mitigation only
Fix from $1,950 2026-05-03
Unclassified HIGH 7.3
CVE-2026-7694

A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown fu…

Mitigation only
Fix from $1,950 2026-05-03
Unclassified MEDIUM 5.0
CVE-2026-7688

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedi…

Mitigation only
Fix from $1,600 2026-05-03
Unclassified MEDIUM 6.3
CVE-2026-7678

A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/ma…

Mitigation only
Fix from $1,600 2026-05-03
Unclassified MEDIUM 6.3
CVE-2026-7672

A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/co…

Mitigation only
Fix from $1,600 2026-05-03
Unclassified HIGH 7.3
CVE-2026-7670

A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manip…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.3
CVE-2026-7632

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.5
CVE-2026-4061

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including,…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.5
CVE-2026-4062

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all version…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.5
CVE-2026-4060

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18.…

Mitigation only
Fix from $1,950 2026-05-02
Ehrd Ctms HIGH 8.8
CVE-2026-7489

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.5
CVE-2026-7649

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based bli…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified MEDIUM 6.5
CVE-2026-6457

The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to,…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified HIGH 7.3
CVE-2026-7592

A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the file /edit_staff.php. Executing…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified MEDIUM 6.3
CVE-2026-7591

A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts …

Mitigation only
Fix from $1,600 2026-05-01
Unclassified MEDIUM 6.5
CVE-2026-42474

SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHelper.php.

Mitigation only
Fix from $1,600 2026-05-01
Mix Php MEDIUM 6.5
CVE-2026-42475

SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.

Fix: after 2.2.17
Fix from $1,600 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7555

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/login.php. Such manip…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7549

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7550

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?actio…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7545

A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commo…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7506

A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/che…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 7.2
CVE-2026-7435

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database executio…

Mitigation only
Fix from $1,950 2026-04-30
Langflow Desktop MEDIUM 6.4
CVE-2026-3346

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to emb…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Unclassified MEDIUM 6.3
CVE-2026-7447

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_custo…

Mitigation only
Fix from $1,600 2026-04-30
Unclassified MEDIUM 6.3
CVE-2026-7410

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?ac…

No fix yet
Fix from $1,600 2026-04-29
Unclassified HIGH 8.2
CVE-2018-25300

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inject…

No fix yet
Fix from $1,950 2026-04-29
Unclassified MEDIUM 6.3
CVE-2026-7391

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action…

Mitigation only
Fix from $1,600 2026-04-29
Unclassified MEDIUM 6.3
CVE-2026-7392

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax…

Mitigation only
Fix from $1,600 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7389

A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.ph…

Mitigation only
Fix from $1,950 2026-04-29