Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.8
CVE-2025-65133

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attac…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-65135

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.p…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-63939

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the si…

Mitigation only
Fix from $2,300 2026-04-14
Fortianalyzer HIGH 7.2
CVE-2025-61848

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, …

Fix: 7.4.9 / 7.6.5+
Fix from $1,950 2026-04-14
Praisonai CRITICAL 9.8
CVE-2026-40315

PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the ta…

Fix: 4.5.133+
Fix from $2,300 2026-04-14
Unclassified HIGH 7.5
CVE-2026-4352

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, a…

Mitigation only
Fix from $1,950 2026-04-14
Unclassified CRITICAL 9.9
CVE-2026-27681

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute cra…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified HIGH 7.7
CVE-2026-32271

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerabil…

Patch available
Fix from $1,950 2026-04-13
Unclassified HIGH 8.7
CVE-2026-32272

Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery:…

Patch available
Fix from $1,950 2026-04-13
Unclassified MEDIUM 6.3
CVE-2026-6202

A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipula…

Mitigation only
Fix from $1,600 2026-04-13
Unclassified MEDIUM 6.3
CVE-2026-6191

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Exec…

Mitigation only
Fix from $1,600 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6193

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The m…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6189

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /aj…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified MEDIUM 6.3
CVE-2026-6190

A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /employees.php.…

Mitigation only
Fix from $1,600 2026-04-13
Unclassified HIGH 7.3
CVE-2026-36948

Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6187

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6188

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_…

Mitigation only
Fix from $1,950 2026-04-13
Pandora Fms HIGH 8.8
CVE-2026-34186

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora F…

Fix: 800.1+
Fix from $1,950 2026-04-13
Pandora Fms HIGH 8.8
CVE-2026-30813

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora F…

Fix: 800.1+
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6182

A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of t…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6183

A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of th…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6167

A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The mani…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 8.6
CVE-2026-3830

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, …

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6166

A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified MEDIUM 6.8
CVE-2025-15441

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which coul…

Mitigation only
Fix from $1,600 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6164

A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Perfo…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6165

A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Log…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6163

A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6161

A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the compone…

Mitigation only
Fix from $1,950 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6153

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetail…

Mitigation only
Fix from $1,950 2026-04-13