Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-4625

A flaw has been found in SourceCodester Online Admission System 1.0. This affects an unknown function of the file /programmes.php. Executing a manipu…

Mitigation only
Fix from $1,950 2026-03-24
Unclassified HIGH 7.3
CVE-2026-4624

A vulnerability was detected in SourceCodester Online Library Management System 1.0. The impacted element is an unknown function of the file /home.ph…

Mitigation only
Fix from $1,950 2026-03-24
Unclassified MEDIUM 6.5
CVE-2026-3079

The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_p…

Mitigation only
Fix from $1,600 2026-03-24
Unclassified HIGH 7.3
CVE-2026-4615

A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the file /search.php. Such manip…

Mitigation only
Fix from $1,950 2026-03-24
Unclassified HIGH 7.3
CVE-2026-4613

A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation …

Mitigation only
Fix from $1,950 2026-03-24
Unclassified MEDIUM 6.3
CVE-2026-4614

A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/sub…

Mitigation only
Fix from $1,600 2026-03-24
Unclassified HIGH 7.5
CVE-2026-4306

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to i…

Mitigation only
Fix from $1,950 2026-03-23
Unclassified MEDIUM 6.5
CVE-2026-2412

The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified HIGH 7.3
CVE-2026-4612

A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/ind…

Mitigation only
Fix from $1,950 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4597

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the file src/main/java/com/geners…

Mitigation only
Fix from $1,600 2026-03-23
Avideo MEDIUM 6.5
CVE-2026-33723

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concate…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo HIGH 8.8
CVE-2026-33651

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule…

Fix: after 26.0
Fix from $1,950 2026-03-23
Unclassified HIGH 7.3
CVE-2026-4594

A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-…

Mitigation only
Fix from $1,950 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4593

A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xy…

Mitigation only
Fix from $1,600 2026-03-23
Avideo HIGH 7.5
CVE-2026-33485

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo CRITICAL 9.8
CVE-2026-33352

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` …

Fix: 26.0+
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.3
CVE-2025-41008

SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client'…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.3
CVE-2025-41007

SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in th…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified HIGH 7.5
CVE-2026-32969

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to i…

Mitigation only
Fix from $1,950 2026-03-23
Simple Laundry System CRITICAL 9.8
CVE-2026-4581

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the compone…

Mitigation only
Fix from $2,300 2026-03-23
Simple Laundry System CRITICAL 9.8
CVE-2026-4580

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php o…

Mitigation only
Fix from $2,300 2026-03-23
Simple Laundry System CRITICAL 9.8
CVE-2026-4579

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the compon…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4573

A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_ha…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4574

A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Up…

Mitigation only
Fix from $1,600 2026-03-23
Sales And Inventory System MEDIUM 6.5
CVE-2026-4571

A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of t…

No fix yet
Fix from $1,600 2026-03-23
Sales And Inventory System MEDIUM 6.5
CVE-2026-4572

A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /vi…

No fix yet
Fix from $1,600 2026-03-23
Sales And Inventory System HIGH 8.8
CVE-2026-4570

A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of t…

No fix yet
Fix from $1,950 2026-03-23
Sales And Inventory System MEDIUM 6.5
CVE-2026-4569

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of t…

No fix yet
Fix from $1,600 2026-03-23
Sales And Inventory System MEDIUM 6.5
CVE-2026-4568

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the …

No fix yet
Fix from $1,600 2026-03-23
Unclassified HIGH 7.5
CVE-2026-2580

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injecti…

Mitigation only
Fix from $1,950 2026-03-23