Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-7128

A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of t…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7117

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. E…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7118

A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 3…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7114

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This ma…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7115

A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified CRITICAL 9.3
CVE-2026-22336

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This i…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7087

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7088

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /aj…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7077

A vulnerability was identified in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /edit_parcel.ph…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7074

A vulnerability has been found in itsourcecode Construction Management System 1.0. This vulnerability affects unknown code of the file /execute1.php.…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7075

A vulnerability was found in itsourcecode Construction Management System 1.0. This issue affects some unknown processing of the file /locations.php. …

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7076

A vulnerability was determined in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /edit_branch.php. Executing…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7072

A vulnerability was detected in CodePanda Source canteen_management_system 1.0. Affected by this issue is some unknown functionality of the file /api…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7073

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /execute.php. This manipulation of…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7070

A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a …

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7063

A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process…

Mitigation only
Fix from $1,950 2026-04-26
Unclassified HIGH 7.3
CVE-2026-7060

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file…

Patch available
Fix from $1,950 2026-04-26
Coze Studio HIGH 8.8
CVE-2026-7023

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/doma…

Fix: after 0.5.1
Fix from $1,950 2026-04-26
Unclassified HIGH 7.3
CVE-2026-7002

A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax…

Mitigation only
Fix from $1,950 2026-04-25
Unclassified MEDIUM 6.3
CVE-2026-6991

A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexe…

Mitigation only
Fix from $1,600 2026-04-25
Unclassified MEDIUM 6.3
CVE-2026-6982

A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file s…

Mitigation only
Fix from $1,600 2026-04-25
Saltcorn CRITICAL 9.9
CVE-2026-41478

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability …

Fix: 1.4.6 / 1.5.6+
Fix from $2,300 2026-04-24
Roxy Wi CRITICAL 9.8
CVE-2026-33078

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
Xibo HIGH 8.1
CVE-2026-31952

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 …

Fix: 4.4.1+
Fix from $1,950 2026-04-24
Jizhicms CRITICAL 9.8
CVE-2025-50229

Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

Mitigation only
Fix from $2,300 2026-04-23
Socialengine CRITICAL 9.8
CVE-2026-41460

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input p…

Fix: after 7.8.0
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-6887

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attac…

Mitigation only
Fix from $2,300 2026-04-23
Rocket.chat CRITICAL 9.8
CVE-2026-29198

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover o…

Fix: 7.10.9 / 7.11.6+
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.1
CVE-2026-41167

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by in…

Patch available
Fix from $2,300 2026-04-22
Unclassified MEDIUM 6.5
CVE-2026-6833

The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read da…

Mitigation only
Fix from $1,600 2026-04-22