Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Mikroorm CRITICAL 9.8
CVE-2026-34220

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a…

Fix: 6.6.10 / 7.0.6+
Fix from $2,300 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5198

A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.p…

Mitigation only
Fix from $1,950 2026-03-31
Unclassified CRITICAL 9.3
CVE-2026-4317

SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated at…

Mitigation only
Fix from $2,300 2026-03-31
Unclassified MEDIUM 6.3
CVE-2026-5197

A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. T…

Mitigation only
Fix from $1,600 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5195

A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the component User Registration H…

Mitigation only
Fix from $1,950 2026-03-31
Unclassified MEDIUM 6.3
CVE-2026-5196

A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The ma…

Mitigation only
Fix from $1,600 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5182

A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teacher Record System of the compo…

Mitigation only
Fix from $1,950 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5180

A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?ac…

Mitigation only
Fix from $1,950 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5179

A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of the file /admin/login.php. The …

Mitigation only
Fix from $1,950 2026-03-31
Scitokens Library CRITICAL 9.8
CVE-2026-32714

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL In…

Fix: 1.9.6+
Fix from $2,300 2026-03-31
Basercms CRITICAL 9.8
CVE-2026-27697

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been pa…

Fix: 5.2.3+
Fix from $2,300 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5150

A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewin_cos…

Mitigation only
Fix from $1,950 2026-03-30
Unclassified HIGH 7.3
CVE-2026-5147

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-web…

Mitigation only
Fix from $1,950 2026-03-30
Schemahero HIGH 7.4
CVE-2026-33643

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go.

Fix: after 0.23.0
Fix from $1,950 2026-03-30
Schemahero HIGH 7.4
CVE-2026-29953

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins/postgres/lib/column.go.

Fix: after 0.23.0
Fix from $1,950 2026-03-30
Accounting System CRITICAL 9.8
CVE-2026-5035

A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Param…

Mitigation only
Fix from $2,300 2026-03-29
Accounting System CRITICAL 9.8
CVE-2026-5034

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of …

Mitigation only
Fix from $2,300 2026-03-29
Accounting System CRITICAL 9.8
CVE-2026-5033

A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_cos…

Mitigation only
Fix from $2,300 2026-03-29
Simple Food Order System CRITICAL 9.8
CVE-2026-5019

A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality …

Mitigation only
Fix from $2,300 2026-03-29
Simple Food Order System CRITICAL 9.8
CVE-2026-5018

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the …

Mitigation only
Fix from $2,300 2026-03-28
Simple Food Order System CRITICAL 9.8
CVE-2026-5017

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of t…

Mitigation only
Fix from $2,300 2026-03-28
Unclassified HIGH 7.3
CVE-2026-4996

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/up…

Mitigation only
Fix from $1,950 2026-03-28
Wegia HIGH 8.8
CVE-2026-33991

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` o…

Fix: 3.6.7+
Fix from $1,950 2026-03-27
Unclassified MEDIUM 6.3
CVE-2026-4970

A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of th…

Mitigation only
Fix from $1,600 2026-03-27
Fleet HIGH 8.1
CVE-2026-34385

Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pi…

Fix: 4.81.0+
Fix from $1,950 2026-03-27
Fleet HIGH 8.8
CVE-2026-34386

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows…

Fix: 4.81.0+
Fix from $1,950 2026-03-27
Avideo CRITICAL 9.1
CVE-2026-34374

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by…

Fix: after 26.0
Fix from $2,300 2026-03-27
Unclassified MEDIUM 6.3
CVE-2026-4966

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=e…

Mitigation only
Fix from $1,600 2026-03-27
Avideo HIGH 8.8
CVE-2026-33767

WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL qu…

Fix: after 26.0
Fix from $1,950 2026-03-27
Avideo CRITICAL 9.8
CVE-2026-33770

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` con…

Fix: after 26.0
Fix from $2,300 2026-03-27