Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Frappe CRITICAL 9.8
CVE-2026-31877

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i…

Fix: 14.99.0 / 15.84.0+
Fix from $2,300 2026-03-11
Unclassified HIGH 8.2
CVE-2019-25486

Varient 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro…

No fix yet
Fix from $1,950 2026-03-11
Parse Server CRITICAL 9.8
CVE-2026-31871

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL inje…

Fix: 8.6.31 / 9.6.0+
Fix from $2,300 2026-03-11
Parse Server CRITICAL 9.8
CVE-2026-31856

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the P…

Fix: 8.6.29 / 9.6.0+
Fix from $2,300 2026-03-11
Craft Cms HIGH 8.8
CVE-2026-31858

Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to …

Fix: 5.9.9+
Fix from $1,950 2026-03-11
Parse Server CRITICAL 9.8
CVE-2026-31840

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacke…

Fix: 8.6.28 / 9.6.0+
Fix from $2,300 2026-03-11
Unclassified HIGH 7.5
CVE-2026-3496

The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up to, and including, 4.0.3. Thi…

Mitigation only
Fix from $1,950 2026-03-11
University Management System CRITICAL 9.8
CVE-2026-3944

A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /att_add.php. Th…

Mitigation only
Fix from $2,300 2026-03-11
Unclassified HIGH 7.5
CVE-2026-1708

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versi…

Mitigation only
Fix from $1,950 2026-03-11
Video Station MEDIUM 6.7
CVE-2024-14025

An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administr…

Fix: 5.8.2+
Fix from $1,600 2026-03-11
Koha HIGH 8.8
CVE-2026-31844

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due t…

Fix: 24.11.12 / 25.05.07+
Fix from $1,950 2026-03-11
Unclassified HIGH 7.5
CVE-2026-3222

The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including…

Mitigation only
Fix from $1,950 2026-03-11
Unclassified HIGH 7.5
CVE-2026-2413

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4…

Mitigation only
Fix from $1,950 2026-03-11
Sylius MEDIUM 5.3
CVE-2026-31825

Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user…

Fix: 1.9.12 / 1.10.16+
Fix from $1,600 2026-03-10
Sequelize HIGH 7.5
CVE-2026-30951

Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverse…

Fix: 6.37.8+
Fix from $1,950 2026-03-10
Craft Commerce HIGH 8.8
CVE-2026-29172

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables t…

Fix: 4.10.2 / 5.5.3+
Fix from $1,950 2026-03-10
Craft Commerce HIGH 8.8
CVE-2026-29174

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table da…

Fix: 5.5.3+
Fix from $1,950 2026-03-10
Buk Ts G Gas Station Automation System CRITICAL 9.8
CVE-2026-3843

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuratio…

Fix: 2.10.2+
Fix from $2,300 2026-03-10
Glances CRITICAL 9.8
CVE-2026-30930

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string co…

Fix: 4.5.1+
Fix from $2,300 2026-03-10
Sql Server 2016 HIGH 8.8
CVE-2026-26116

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6480.4 / 13.0.7075.5+
Fix from $1,950 2026-03-10
Limesurvey HIGH 7.5
CVE-2025-56421

SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

Fix: after 6.15.3
Fix from $1,950 2026-03-10
Fortianalyzer HIGH 7.2
CVE-2025-49784

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, …

Fix: 7.4.5 / 7.4.8+
Fix from $1,950 2026-03-10
Unclassified MEDIUM 6.4
CVE-2026-27684

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL cod…

Mitigation only
Fix from $1,600 2026-03-10
Easy7 Cms CRITICAL 9.8
CVE-2026-3818

A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This mani…

Mitigation only
Fix from $2,300 2026-03-09
Eventobot CRITICAL 9.8
CVE-2025-40639

A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases thr…

Mitigation only
Fix from $2,300 2026-03-09
Resort Reservation System HIGH 8.8
CVE-2026-3806

A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_r…

No fix yet
Fix from $1,950 2026-03-09
Sales And Inventory System HIGH 8.8
CVE-2026-3793

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.p…

No fix yet
Fix from $1,950 2026-03-09
Sales And Inventory System HIGH 8.8
CVE-2026-3792

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the comp…

No fix yet
Fix from $1,950 2026-03-09
Sales And Inventory System HIGH 8.8
CVE-2026-3791

A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file das…

No fix yet
Fix from $1,950 2026-03-09
Sales And Inventory System HIGH 8.8
CVE-2026-3790

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_…

No fix yet
Fix from $1,950 2026-03-09