Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Online Food Ordering System HIGH 8.3
CVE-2026-30534

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

No fix yet
Fix from $1,950 2026-03-27
Online Food Ordering System HIGH 8.8
CVE-2026-30529

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). …

No fix yet
Fix from $1,950 2026-03-27
Online Food Ordering System CRITICAL 9.8
CVE-2026-30530

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer actio…

Mitigation only
Fix from $2,300 2026-03-27
Online Food Ordering System HIGH 8.8
CVE-2026-30531

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category actio…

No fix yet
Fix from $1,950 2026-03-27
Online Food Ordering System CRITICAL 9.8
CVE-2026-30532

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.

Mitigation only
Fix from $2,300 2026-03-27
Online Food Ordering System CRITICAL 9.8
CVE-2026-30533

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.

Mitigation only
Fix from $2,300 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4955

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. T…

Mitigation only
Fix from $1,950 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4956

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePr…

Mitigation only
Fix from $1,950 2026-03-27
Unclassified MEDIUM 6.3
CVE-2026-4954

A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/Conten…

Mitigation only
Fix from $1,600 2026-03-27
Group Office HIGH 8.8
CVE-2026-33755

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated …

Fix: 6.8.158 / 25.0.92+
Fix from $1,950 2026-03-27
Grafana CRITICAL 9.1
CVE-2026-27876

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a…

Fix: 11.6.0 / 12.0.0+
Fix from $2,300 2026-03-27
Dovecot HIGH 8.2
CVE-2026-24031

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for…

Fix: 2.4.3 / 3.1.4+
Fix from $1,950 2026-03-27
Spring Ai HIGH 7.5
CVE-2026-22743

Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is…

Fix: 1.0.5 / 1.1.4+
Fix from $1,950 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4910

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /…

Mitigation only
Fix from $1,950 2026-03-27
Simple Laundry System CRITICAL 9.8
CVE-2026-4908

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the…

Mitigation only
Fix from $2,300 2026-03-27
Mobile Security Framework MEDIUM 6.5
CVE-2026-33545

MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 5…

Fix: 4.4.6+
Fix from $1,600 2026-03-26
Inventree MEDIUM 6.5
CVE-2026-33531

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows …

Fix: 1.2.6+
Fix from $1,600 2026-03-26
Keto HIGH 7.2
CVE-2026-33505

Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is v…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Recipes MEDIUM 6.5
CVE-2026-33153

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpo…

Fix: 2.6.0+
Fix from $1,600 2026-03-26
Fuel Cms HIGH 7.7
CVE-2026-30463

Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.

No fix yet
Fix from $1,950 2026-03-26
Hydra HIGH 7.2
CVE-2026-33504

Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrus…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Kratos HIGH 7.2
CVE-2026-33503

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API i…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Kysely HIGH 8.1
CVE-2026-33468

Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes si…

Fix: 0.28.14+
Fix from $1,950 2026-03-26
Kysely HIGH 8.1
CVE-2026-33442

Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method in Kysely's query compiler es…

Fix: 0.28.14+
Fix from $1,950 2026-03-26
Unclassified MEDIUM 6.3
CVE-2026-4876

A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified HIGH 7.5
CVE-2026-2511

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55262

HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab…

Mitigation only
Fix from $1,950 2026-03-26
Qdpm HIGH 8.2
CVE-2018-25208

qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through …

Fix: after 9.1
Fix from $1,950 2026-03-26
Unclassified HIGH 8.2
CVE-2018-25209

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries…

No fix yet
Fix from $1,950 2026-03-26
Unclassified HIGH 8.2
CVE-2018-25203

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting…

No fix yet
Fix from $1,950 2026-03-26