Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified MEDIUM 5.8
CVE-2026-72775

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifi…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-72750

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates ex…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72609

An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_re…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72607

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_ba…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72608

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_cr…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72562

An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-72599

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. Th…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72558

An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE cla…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-72550

An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statement…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-19425

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66770

Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72908

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13294

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke…

No fix yet
Fix from $5,750 2026-08-10
Metabase CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …

Fix: 0.58.24 / 0.59.21+
Fix from $5,750 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 7.1
CVE-2026-72731

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-63106

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72565

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read ar…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-19053

The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unau…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.6
CVE-2026-19049

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.8
CVE-2026-16949

The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthent…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.3
CVE-2026-19384

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admi…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-19364

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorcon…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.3
CVE-2026-19355

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/lis…

No fix yet
Fix from $4,900 2026-08-09
Unclassified MEDIUM 6.3
CVE-2026-19354

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file c…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.3
CVE-2026-19351

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/Sel…

No fix yet
Fix from $4,900 2026-08-09
Unclassified MEDIUM 6.3
CVE-2026-19347

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.3
CVE-2026-19344

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/co…

No fix yet
Fix from $4,900 2026-08-09
Unclassified HIGH 7.3
CVE-2026-19343

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Admi…

No fix yet
Fix from $4,900 2026-08-09