Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Freepbx HIGH 8.8
CVE-2026-28284

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vuln…

Fix: 16.0.10 / 17.0.5+
Fix from $1,950 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-2893

The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versi…

Mitigation only
Fix from $1,600 2026-03-05
Unclassified CRITICAL 9.3
CVE-2026-28115

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy St…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified HIGH 8.5
CVE-2026-27428

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle Booking eagle-booking allows…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified HIGH 8.5
CVE-2026-27373

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome tablesome allows Blind SQL In…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified CRITICAL 9.3
CVE-2025-69338

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode Core riode-core allows Blind S…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified MEDIUM 6.5
CVE-2026-20001

A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an aff…

Mitigation only
Fix from $1,600 2026-03-04
Secure Firewall Management Center HIGH 8.1
CVE-2026-20002

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injec…

Fix: after 7.7.10.1
Fix from $1,950 2026-03-04
Phpads HIGH 7.1
CVE-2019-25503

PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code…

No fix yet
Fix from $1,950 2026-03-04
Unclassified HIGH 8.2
CVE-2019-25504

NCrypted Jobgator contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $1,950 2026-03-04
Tradebox HIGH 7.1
CVE-2019-25505

Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through…

No fix yet
Fix from $1,950 2026-03-04
Freesms CRITICAL 9.8
CVE-2019-25506

FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass au…

Fix: after 2.1.2
Fix from $2,300 2026-03-04
Unclassified HIGH 8.2
CVE-2019-25507

Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injectin…

No fix yet
Fix from $1,950 2026-03-04
Simplejobscript HIGH 8.2
CVE-2019-25498

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

Fix: after 1.66
Fix from $1,950 2026-03-04
Simplejobscript CRITICAL 9.8
CVE-2019-25499

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

Fix: after 1.66
Fix from $2,300 2026-03-04
Simplejobscript HIGH 8.2
CVE-2019-25500

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

Fix: after 1.66
Fix from $1,950 2026-03-04
Simplejobscript HIGH 8.2
CVE-2019-25501

Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code throug…

Fix: after 1.66
Fix from $1,950 2026-03-04
Hardware Read \& Write Utility CRITICAL 9.8
CVE-2025-66678

An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitr…

Fix: after 1.25.11.26
Fix from $2,300 2026-03-04
Databasir CRITICAL 9.8
CVE-2025-66944

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in t…

Fix: after 1.0.7
Fix from $2,300 2026-03-04
Unclassified HIGH 7.5
CVE-2023-7337

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatu…

Mitigation only
Fix from $1,950 2026-03-04
Unclassified MEDIUM 6.5
CVE-2026-2363

The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts…

Mitigation only
Fix from $1,600 2026-03-04
Unclassified MEDIUM 6.5
CVE-2026-1651

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, …

Mitigation only
Fix from $1,600 2026-03-04
College Management System HIGH 7.2
CVE-2026-3487

A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.p…

No fix yet
Fix from $1,950 2026-03-03
College Management System HIGH 7.2
CVE-2026-3486

A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /admin/student-fee.…

No fix yet
Fix from $1,950 2026-03-03
Simple Logistic Hub Parcel\'s Management System HIGH 7.2
CVE-2026-26892

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

No fix yet
Fix from $1,950 2026-03-03
Impact HIGH 8.2
CVE-2021-35484

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endp…

Fix: after 19.11.2.10-20210118042150283
Fix from $1,950 2026-03-03
Renren Security CRITICAL 9.8
CVE-2025-70821

renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component

Fix: after 5.5.0
Fix from $2,300 2026-03-03
Unclassified MEDIUM 6.5
CVE-2026-1487

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all ve…

Mitigation only
Fix from $1,600 2026-03-03
Simple Food Order System CRITICAL 9.8
CVE-2026-26713

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Food Order System CRITICAL 9.8
CVE-2026-26712

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

Mitigation only
Fix from $2,300 2026-03-02