Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Chyrp HIGH 7.5
CVE-2025-69768

SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component

Fix: after 2.5.2
Fix from $1,950 2026-03-16
Unica CRITICAL 9.8
CVE-2025-62319

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE…

Fix: 25.1.1.0.1+
Fix from $2,300 2026-03-16
Aion MEDIUM 5.3
CVE-2025-52646

HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper valid…

Fix: 2.1.2+
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4241

A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/time-tab…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4237

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4232

A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /res…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4234

A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4235

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. T…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4236

A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/inde…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4229

A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vect…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4230

A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/legacy/flask/__init__.py of t…

Mitigation only
Fix from $1,600 2026-03-16
Payroll Management System CRITICAL 9.8
CVE-2026-4223

A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4190

A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulat…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-4173

A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. This vulnerability affects the function exportTable/exportTableColumnComment/exportView/exp…

Mitigation only
Fix from $1,600 2026-03-16
Wakyma MEDIUM 6.5
CVE-2026-3021

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/emplea…

Mitigation only
Fix from $1,600 2026-03-16
Wakyma MEDIUM 6.5
CVE-2026-3022

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/gene…

Mitigation only
Fix from $1,600 2026-03-16
Wakyma HIGH 8.8
CVE-2026-3023

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. Th…

Mitigation only
Fix from $1,950 2026-03-16
Anythingllm HIGH 8.8
CVE-2026-32628

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a …

Fix: after 1.11.1
Fix from $1,950 2026-03-16
Aion HIGH 7.3
CVE-2025-52637

HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper valid…

Fix: 2.1.2+
Fix from $1,950 2026-03-16
Realtyscript CRITICAL 9.8
CVE-2015-20121

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by …

Mitigation only
Fix from $2,300 2026-03-16
Realtyscript CRITICAL 9.8
CVE-2015-20120

Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified HIGH 7.6
CVE-2026-32458

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL In…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 7.6
CVE-2026-32459

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bump…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.5
CVE-2026-32433

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-conta…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.5
CVE-2026-32422

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart al…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 7.6
CVE-2026-32418

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Bli…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.5
CVE-2026-32399

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-lib…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.5
CVE-2026-32368

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.5
CVE-2026-32365

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archive…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.5
CVE-2026-32366

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categ…

Mitigation only
Fix from $1,950 2026-03-13