Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.1
CVE-2026-18473

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a…

No fix yet
Fix from $5,750 2026-08-09
Unclassified HIGH 8.6
CVE-2026-17044

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading t…

No fix yet
Fix from $4,900 2026-08-09
Unclassified HIGH 8.1
CVE-2026-17017

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an A…

No fix yet
Fix from $4,900 2026-08-09
Unclassified HIGH 7.7
CVE-2026-16589

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its aut…

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 7.3
CVE-2026-19231

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /adm…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.7
CVE-2026-64636

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the pan…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.3
CVE-2026-19211

A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Per…

No fix yet
Fix from $1,950 2026-08-07
Postgrex HIGH 8.2
CVE-2026-66838

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via t…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.3
CVE-2026-19196

A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.1
CVE-2026-15361

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated …

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19067

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatmen…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19068

A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /treatmentdeta…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19069

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /treatmentrec…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19070

A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipul…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19071

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipula…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.3
CVE-2026-19062

A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/se…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.6
CVE-2026-3430

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unaut…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-66447

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.5
CVE-2026-65569

Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-65546

Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.5
CVE-2026-65547

Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

No fix yet
Fix from $2,300 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…

Fix: after 1.6.3
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19020

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.3
CVE-2026-19021

A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-16065

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL st…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-12713

The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin…

No fix yet
Fix from $2,300 2026-08-06