Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.6
CVE-2026-42646

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind …

Mitigation only
Fix from $1,950 2026-04-29
Unclassified CRITICAL 10.0
CVE-2026-3325

SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The v…

Mitigation only
Fix from $2,300 2026-04-29
Proftpd HIGH 8.1
CVE-2026-42167

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER reques…

Fix: after 1.3.9b
Fix from $1,950 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7290

A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boot/jeecg-boot-base-core/src/ma…

Patch available
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7266

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7267

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation …

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7268

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?ac…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7265

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file …

Mitigation only
Fix from $1,600 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7264

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?ac…

Mitigation only
Fix from $1,600 2026-04-28
Spring Ai HIGH 8.8
CVE-2026-40978

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affecte…

Fix: 1.0.6 / 1.1.5+
Fix from $1,950 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7229

A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7225

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7226

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7227

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login.…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7228

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7224

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7206

A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. …

Patch available
Fix from $1,950 2026-04-28
Unclassified MEDIUM 6.3
CVE-2026-7196

A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipul…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7199

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7194

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?acti…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified CRITICAL 9.4
CVE-2024-46636

NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category …

Mitigation only
Fix from $2,300 2026-04-27
Unclassified HIGH 7.0
CVE-2026-5394

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and …

Patch available
Fix from $1,950 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7148

A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the arg…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.5
CVE-2021-36438

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7143

A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-41462

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is d…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7131

A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /log…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7130

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?ac…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7126

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?act…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7127

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /ajax.p…

Mitigation only
Fix from $1,950 2026-04-27