Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified MEDIUM 6.9
CVE-2026-41457

OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arb…

Patch available
Fix from $1,600 2026-04-22
Sync Service HIGH 8.8
CVE-2026-40906

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based…

Fix: 1.5.0+
Fix from $1,950 2026-04-21
Frappe Hr MEDIUM 6.5
CVE-2026-41320

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a …

Fix: 14.38.1 / 15.54.0+
Fix from $1,600 2026-04-21
Unclassified CRITICAL 9.1
CVE-2026-40887

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified HIGH 7.2
CVE-2026-40871EPSS 10%

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerabili…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.3
CVE-2025-41029

SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete da…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified MEDIUM 6.5
CVE-2026-6674

The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-04-21
Glances MEDIUM 6.3
CVE-2026-35588

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassan…

Fix: 4.5.4+
Fix from $1,600 2026-04-21
Unclassified CRITICAL 9.4
CVE-2026-39109

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the lo…

Mitigation only
Fix from $2,300 2026-04-20
Unclassified HIGH 8.2
CVE-2026-39110

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgo…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.5
CVE-2026-39111

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot pa…

Mitigation only
Fix from $1,950 2026-04-20
Doris Mcp Server MEDIUM 5.3
CVE-2025-66335

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio…

Fix: 0.6.1+
Fix from $1,600 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6629

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file …

Mitigation only
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6628

A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query…

Mitigation only
Fix from $1,600 2026-04-20
Easyflow .net CRITICAL 9.8
CVE-2026-5963

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r…

Fix: after 6.6.17
Fix from $2,300 2026-04-20
Easyflow .net CRITICAL 9.8
CVE-2026-5964

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r…

Fix: after 6.6.17
Fix from $2,300 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6595

A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability aff…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6562

A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a ma…

Mitigation only
Fix from $1,950 2026-04-19
Unclassified HIGH 7.1
CVE-2026-40482

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via uns…

Patch available
Fix from $1,950 2026-04-18
Unclassified HIGH 8.8
CVE-2026-40285

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. T…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified CRITICAL 9.8
CVE-2026-37749

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication …

Mitigation only
Fix from $2,300 2026-04-17
Unclassified HIGH 7.3
CVE-2026-6490

A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/del…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified MEDIUM 6.3
CVE-2026-6488

A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file a…

Mitigation only
Fix from $1,600 2026-04-17
Pro Cloud Server CRITICAL 9.8
CVE-2025-15625

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Mitigation only
Fix from $2,300 2026-04-17
Cubecart CRITICAL 9.8
CVE-2026-34018

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

Fix: 6.6.0+
Fix from $2,300 2026-04-17
Unclassified MEDIUM 6.5
CVE-2026-6080

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the …

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.5
CVE-2026-4817

The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'o…

Mitigation only
Fix from $1,600 2026-04-17
Dataease HIGH 8.8
CVE-2026-40900

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api…

Fix: 2.10.21+
Fix from $1,950 2026-04-16
Dataease CRITICAL 9.8
CVE-2026-33122

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API dat…

Fix: 2.10.21+
Fix from $2,300 2026-04-16
Dataease HIGH 8.8
CVE-2026-33207

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /dataso…

Fix: 2.10.21+
Fix from $1,950 2026-04-16