Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Weknora CRITICAL 9.8
CVE-2026-30860

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution…

Fix: 0.2.12+
Fix from $2,300 2026-03-07
Unclassified HIGH 7.5
CVE-2025-14353

The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcod…

Mitigation only
Fix from $1,950 2026-03-07
Php Oop Cms Blog CRITICAL 9.8
CVE-2018-25199

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious …

Mitigation only
Fix from $2,300 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25192

GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25196

ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25197

PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious…

No fix yet
Fix from $1,950 2026-03-06
Tina4 Stack CRITICAL 9.8
CVE-2018-25187

Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection a…

Mitigation only
Fix from $2,300 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25188

Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25189

Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to e…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 7.1
CVE-2018-25191

Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting mali…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25179

Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious …

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 7.1
CVE-2018-25180

Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25182

Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inje…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25175

Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25172

Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious cod…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25173

Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code th…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 7.1
CVE-2018-25165

Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting …

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25166

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25167

Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute …

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25163

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious cod…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25161

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting maliciou…

No fix yet
Fix from $1,950 2026-03-06
Siyuan HIGH 8.8
CVE-2026-29073

SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic a…

Fix: after 3.5.9
Fix from $1,950 2026-03-06
Cocoindex CRITICAL 9.8
CVE-2026-28438

CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name befo…

Fix: 0.3.34+
Fix from $2,300 2026-03-06
Ghostfolio CRITICAL 9.8
CVE-2026-28785

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary …

Fix: 2.244.0+
Fix from $2,300 2026-03-06
Chartbrew CRITICAL 9.8
CVE-2026-27005

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3…

Fix: 4.8.3+
Fix from $2,300 2026-03-06
Avideo CRITICAL 9.8
CVE-2026-28501

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec…

Fix: 24.0+
Fix from $2,300 2026-03-06
Unclassified MEDIUM 6.3
CVE-2026-3616

A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modu…

Patch available
Fix from $1,600 2026-03-06
Openreplay CRITICAL 9.8
CVE-2026-28443

OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sor…

Fix: 1.20.0+
Fix from $2,300 2026-03-05
Frappe HIGH 8.8
CVE-2026-29081

Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specia…

Fix: 14.100.1+
Fix from $1,950 2026-03-05
Freepbx HIGH 8.8
CVE-2026-28210

FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. T…

Fix: 16.0.49 / 17.0.7+
Fix from $1,950 2026-03-05