Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-4540

A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of t…

Mitigation only
Fix from $1,950 2026-03-22
Simple Food Order System HIGH 8.8
CVE-2026-4533

A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-t…

No fix yet
Fix from $1,950 2026-03-22
Unclassified MEDIUM 5.3
CVE-2026-4530

A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriev…

Mitigation only
Fix from $1,600 2026-03-22
I Doit HIGH 7.5
CVE-2019-25581

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou…

No fix yet
Fix from $1,950 2026-03-21
Simplepress Cms HIGH 8.2
CVE-2019-25575

SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal…

Fix: after 1.0.7
Fix from $1,950 2026-03-21
Kepler Wallpaper Script HIGH 8.2
CVE-2019-25576

Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti…

No fix yet
Fix from $1,950 2026-03-21
Phptransformer HIGH 8.2
CVE-2019-25578

phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious co…

No fix yet
Fix from $1,950 2026-03-21
Greencms HIGH 8.8
CVE-2019-25573

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious cod…

Fix: after 2.3.0603
Fix from $1,950 2026-03-21
Unclassified MEDIUM 6.3
CVE-2026-4513

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py.…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.5
CVE-2026-4087

The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pprh_update_hints AJAX action i…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 8.8
CVE-2026-3334

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified MEDIUM 6.5
CVE-2026-2503

The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_pos…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 7.5
CVE-2026-2468

The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to, and including, 1.2.12. This …

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 7.2
CVE-2026-2279

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and includin…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 7.5
CVE-2026-1800

The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions…

Mitigation only
Fix from $1,950 2026-03-21
Unclassified HIGH 7.3
CVE-2026-4508

A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberCo…

Mitigation only
Fix from $1,950 2026-03-20
Unclassified MEDIUM 6.3
CVE-2026-4507

A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the file mindsql/core/mindsql_cor…

Mitigation only
Fix from $1,600 2026-03-20
Oneuptime HIGH 8.1
CVE-2026-33142

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection v…

Fix: 10.0.34+
Fix from $1,950 2026-03-20
Unclassified HIGH 7.3
CVE-2026-4504

A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomp…

Mitigation only
Fix from $1,950 2026-03-20
Qurouter MEDIUM 6.7
CVE-2025-62846

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulne…

Mitigation only
Fix from $1,600 2026-03-20
Unclassified MEDIUM 6.3
CVE-2026-4485

A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/search_s…

Mitigation only
Fix from $1,600 2026-03-20
Wegia HIGH 7.2
CVE-2026-33133

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup a…

Patch available
Fix from $1,950 2026-03-20
Wegia HIGH 8.8
CVE-2026-33134

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/…

Fix: 3.6.6+
Fix from $1,950 2026-03-20
Online Doctor Appointment System CRITICAL 9.8
CVE-2026-4473

A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appo…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4472

A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the fi…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4469

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4470

A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4471

A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_em…

Mitigation only
Fix from $2,300 2026-03-20
Avideo Encoder HIGH 8.8
CVE-2026-33025

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_P…

Fix: 8.0+
Fix from $1,950 2026-03-20
Sqlbot HIGH 8.8
CVE-2026-32950

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab…

Fix: 1.7.0+
Fix from $1,950 2026-03-20