Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Erpnext HIGH 7.5
CVE-2026-32954

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-…

Fix: 15.100.0 / 16.8.0+
Fix from $1,950 2026-03-20
Open Source Point Of Sale HIGH 8.8
CVE-2026-32888

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in t…

Fix: after 3.4.2
Fix from $1,950 2026-03-20
Admidio HIGH 8.0
CVE-2026-32813

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configurati…

Fix: 5.0.7+
Fix from $1,950 2026-03-20
Siyuan CRITICAL 9.8
CVE-2026-32767

SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextS…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Suitecrm HIGH 8.8
CVE-2026-33288

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL I…

Fix: 7.15.1 / 8.9.3+
Fix from $1,950 2026-03-20
Kysely HIGH 8.2
CVE-2026-32763

Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation f…

Fix: 0.28.12+
Fix from $1,950 2026-03-20
Suitecrm MEDIUM 6.5
CVE-2026-29096

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when cr…

Fix: 7.15.1 / 8.9.3+
Fix from $1,600 2026-03-19
Suitecrm HIGH 8.8
CVE-2026-29099

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `re…

Fix: 7.15.1 / 8.9.3+
Fix from $1,950 2026-03-19
Unclassified HIGH 8.8
CVE-2026-30711

Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer …

Mitigation only
Fix from $1,950 2026-03-19
Unclassified HIGH 7.5
CVE-2026-3658

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' p…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified CRITICAL 9.3
CVE-2026-27413

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL…

Mitigation only
Fix from $2,300 2026-03-19
Openproject HIGH 7.2
CVE-2026-32698

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL i…

Fix: 16.6.9 / 17.0.6+
Fix from $1,950 2026-03-18
Clipbucket HIGH 8.8
CVE-2026-32321

ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5…

Fix: 5.5.3-80+
Fix from $1,950 2026-03-18
Unclassified HIGH 8.8
CVE-2025-58112

Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an uplo…

Mitigation only
Fix from $1,950 2026-03-18
Glances CRITICAL 9.1
CVE-2026-32611

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export…

Fix: 4.5.2+
Fix from $2,300 2026-03-18
Mura Cms CRITICAL 9.8
CVE-2025-67830

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

Fix: 10.1.4+
Fix from $2,300 2026-03-18
Mura Cms CRITICAL 9.8
CVE-2025-67829

Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.

Fix: 10.1.4+
Fix from $2,300 2026-03-18
Spring Ai HIGH 8.8
CVE-2026-22730

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and …

Fix: 1.0.4 / 1.1.3+
Fix from $1,950 2026-03-18
Kanboard MEDIUM 6.5
CVE-2026-33058

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. At…

Fix: 1.2.51+
Fix from $1,600 2026-03-18
Cockpit MEDIUM 6.5
CVE-2026-31891

Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially af…

Fix: 2.13.5+
Fix from $1,600 2026-03-18
Glpi Inventory HIGH 8.8
CVE-2026-26001

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitiz…

Fix: 1.6.6+
Fix from $1,950 2026-03-18
Glpi HIGH 8.8
CVE-2026-25936

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a S…

Fix: after 11.0.6
Fix from $1,950 2026-03-17
Simple Food Order System CRITICAL 9.8
CVE-2026-4319

A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2026-03-17
Unclassified MEDIUM 5.4
CVE-2026-4324

A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a re…

Mitigation only
Fix from $1,600 2026-03-17
Unclassified HIGH 7.5
CVE-2026-2579

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all v…

Mitigation only
Fix from $1,950 2026-03-17
Unclassified HIGH 7.3
CVE-2026-4287

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /r…

Mitigation only
Fix from $1,950 2026-03-17
Unclassified HIGH 7.3
CVE-2026-4288

A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/d…

Mitigation only
Fix from $1,950 2026-03-17
Unclassified HIGH 7.3
CVE-2026-4289

A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file …

Mitigation only
Fix from $1,950 2026-03-17
Chamilo Lms HIGH 8.8
CVE-2026-30881

Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The pa…

Fix: 1.11.36+
Fix from $1,950 2026-03-16
Chamilo Lms CRITICAL 9.8
CVE-2026-28430

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote at…

Fix: 1.11.34+
Fix from $2,300 2026-03-16