Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Praisonai CRITICAL 9.8
CVE-2026-34934

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with u…

Fix: 4.5.90+
Fix from $2,300 2026-04-03
Kestra CRITICAL 9.0
CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Inje…

Fix: 1.3.7+
Fix from $2,300 2026-04-03
Piwigo HIGH 7.2
CVE-2026-27834

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getLis…

Fix: 16.3.0+
Fix from $1,950 2026-04-03
Piwigo HIGH 7.2
CVE-2026-27885

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affec…

Fix: 16.3.0+
Fix from $1,950 2026-04-03
Piwigo CRITICAL 9.8
CVE-2026-27634

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max…

Fix: 16.3.0+
Fix from $2,300 2026-04-03
Focalboard MEDIUM 6.5
CVE-2026-25773

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reor…

Mitigation only
Fix from $1,600 2026-04-03
Nocobase MEDIUM 6.5
CVE-2026-34825

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase pl…

Fix: 2.0.30+
Fix from $1,600 2026-04-02
Car Rental Project CRITICAL 9.8
CVE-2026-5368

A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the com…

Mitigation only
Fix from $2,300 2026-04-02
Openproject HIGH 8.1
CVE-2026-34717

OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat…

Fix: 17.2.3+
Fix from $1,950 2026-04-02
Online Enrollment System CRITICAL 9.8
CVE-2026-5334

A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=e…

Mitigation only
Fix from $2,300 2026-04-02
Openstamanager HIGH 8.8
CVE-2026-35168

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) mod…

Fix: 2.10.2+
Fix from $1,950 2026-04-02
Openstamanager HIGH 8.8
CVE-2026-28805

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers i…

Fix: 2.10.2+
Fix from $1,950 2026-04-02
Unclassified MEDIUM 6.3
CVE-2026-5328

A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listIt…

Patch available
Fix from $1,600 2026-04-02
Mbconnect24 HIGH 7.5
CVE-2026-33616

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutraliz…

Fix: after 2.19.4
Fix from $1,950 2026-04-02
Mbconnect24 HIGH 7.5
CVE-2026-33614

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization …

Fix: after 2.19.4
Fix from $1,950 2026-04-02
Mbconnect24 CRITICAL 9.1
CVE-2026-33615

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization …

Fix: after 2.19.4
Fix from $2,300 2026-04-02
Unclassified HIGH 7.3
CVE-2026-5322

A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d.…

Mitigation only
Fix from $1,950 2026-04-02
Payload HIGH 8.2
CVE-2026-34747

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An…

Fix: 3.79.1+
Fix from $1,950 2026-04-01
Hi.events HIGH 8.8
CVE-2026-34455

Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository…

Fix: 1.7.1+
Fix from $1,950 2026-04-01
Pandasai HIGH 7.3
CVE-2026-30273

pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.

Fix: after 3.0.0
Fix from $1,950 2026-04-01
Joomla\! HIGH 8.8
CVE-2026-21630

Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

Fix: 5.4.4 / 6.0.4+
Fix from $1,950 2026-04-01
Simple Laundry System CRITICAL 9.8
CVE-2026-5256

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Pa…

Mitigation only
Fix from $2,300 2026-04-01
Simple Laundry System CRITICAL 9.8
CVE-2026-5257

A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php o…

Mitigation only
Fix from $2,300 2026-04-01
Storage Protect Server HIGH 8.8
CVE-2025-13855

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s…

Mitigation only
Fix from $1,950 2026-04-01
Unclassified HIGH 7.3
CVE-2026-5238

A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_…

Mitigation only
Fix from $1,950 2026-04-01
Unclassified MEDIUM 6.5
CVE-2026-4668

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payment…

Mitigation only
Fix from $1,600 2026-04-01
Unclassified HIGH 7.3
CVE-2026-5237

A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $1,950 2026-03-31
Alerta CRITICAL 9.8
CVE-2026-34400

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, …

Fix: 9.1.0+
Fix from $2,300 2026-03-31
Unclassified MEDIUM 6.3
CVE-2026-5206

A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the componen…

Mitigation only
Fix from $1,600 2026-03-31
Loan Management System MEDIUM 5.4
CVE-2026-30520

A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specific…

No fix yet
Fix from $1,600 2026-03-31