Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Dataease HIGH 8.8
CVE-2026-33084

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort pa…

Fix: 2.10.21+
Fix from $1,950 2026-04-16
Dataease HIGH 8.8
CVE-2026-33121

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API dat…

Fix: 2.10.21+
Fix from $1,950 2026-04-16
Dataease CRITICAL 9.8
CVE-2026-33082

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export f…

Fix: 2.10.21+
Fix from $2,300 2026-04-16
Dataease HIGH 8.8
CVE-2026-33083

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDi…

Fix: 2.10.21+
Fix from $1,950 2026-04-16
Unclassified HIGH 7.2
CVE-2026-37341

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.

No fix yet
Fix from $1,950 2026-04-16
Unclassified HIGH 7.2
CVE-2026-37342

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.

Mitigation only
Fix from $1,950 2026-04-16
Unclassified HIGH 7.2
CVE-2026-37343

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.

Mitigation only
Fix from $1,950 2026-04-16
Unclassified HIGH 7.2
CVE-2026-37344

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.

Mitigation only
Fix from $1,950 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-37345

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.1
CVE-2026-37347

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified HIGH 7.3
CVE-2026-37336

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.

Mitigation only
Fix from $1,950 2026-04-16
Unclassified HIGH 7.3
CVE-2026-37337

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.

Mitigation only
Fix from $1,950 2026-04-16
Unclassified CRITICAL 9.4
CVE-2026-37338

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-37339

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-37340

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified HIGH 8.1
CVE-2026-5785

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated S…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified HIGH 7.5
CVE-2026-3489

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified MEDIUM 6.5
CVE-2026-3773

The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-04-16
Unclassified HIGH 7.5
CVE-2026-3599

The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-js…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified HIGH 8.6
CVE-2026-30995

Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.

Mitigation only
Fix from $1,950 2026-04-15
Unity Connection MEDIUM 6.5
CVE-2026-20061

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injec…

Fix: after 12.5
Fix from $1,600 2026-04-15
Unclassified HIGH 7.6
CVE-2025-63029

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marke…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified HIGH 8.5
CVE-2026-40744

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-li…

Mitigation only
Fix from $1,950 2026-04-15
Unclassified HIGH 7.6
CVE-2026-40745

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes…

Mitigation only
Fix from $1,950 2026-04-15
Chamilo Lms HIGH 7.2
CVE-2026-33714

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint…

Mitigation only
Fix from $1,950 2026-04-14
Sql Server 2016 HIGH 7.8
CVE-2026-32176

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6485.1 / 13.0.7080.1+
Fix from $1,950 2026-04-14
Sql Server 2016 HIGH 7.8
CVE-2026-32167

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6485.1 / 13.0.7080.1+
Fix from $1,950 2026-04-14
Fortiddos F HIGH 8.8
CVE-2026-39815

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may …

Fix: 7.2.3+
Fix from $1,950 2026-04-14
Forticlientems MEDIUM 6.7
CVE-2026-39809

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, …

Fix: 7.2.13 / 7.4.6+
Fix from $1,600 2026-04-14
Unclassified HIGH 7.1
CVE-2026-38528

Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.

Mitigation only
Fix from $1,950 2026-04-14