Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Glpi HIGH 8.8
CVE-2026-29047

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection …

Fix: 10.0.24 / 11.0.6+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5660

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5649

A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5645

A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.ph…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5646

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file logi…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5648

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the …

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5641

A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-ima…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5637

A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown code of the file /message_admin…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5639

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the c…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5640

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/updat…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5636

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the com…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5634

A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /book_…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5635

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the fil…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5620

A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5606

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5596

A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool…

Mitigation only
Fix from $1,600 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25694

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25696

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the lan…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25698

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25700

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sor…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25702

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25704

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the fil…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25688

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $2,300 2026-04-05
Kados HIGH 8.2
CVE-2019-25690

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng…

No fix yet
Fix from $1,950 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25692

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id…

No fix yet
Fix from $2,300 2026-04-05
Advance Gift Shop Pro Script CRITICAL 9.8
CVE-2019-25680

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by …

Fix: after 2.0.3
Fix from $2,300 2026-04-05
Opendocman HIGH 8.2
CVE-2019-25684

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t…

Fix: after 1.3.4
Fix from $1,950 2026-04-05
Cmssite CRITICAL 9.8
CVE-2019-25674

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…

Mitigation only
Fix from $2,300 2026-04-05
Edirectory HIGH 7.5
CVE-2019-25675

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose s…

Fix: after 1.0
Fix from $1,950 2026-04-05
Ask Expert Script CRITICAL 9.8
CVE-2019-25676

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code…

Mitigation only
Fix from $2,300 2026-04-05