Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Openemr HIGH 8.8
CVE-2026-23627

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vul…

Fix: 8.0.0+
Fix from $1,950 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-24908

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vul…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Unclassified MEDIUM 6.5
CVE-2026-25554

OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_autho…

Patch available
Fix from $1,600 2026-02-25
Unclassified CRITICAL 9.8
CVE-2026-27847

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inj…

Mitigation only
Fix from $2,300 2026-02-25
Developer Hub MEDIUM 6.5
CVE-2026-3118

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation…

Mitigation only
Fix from $1,600 2026-02-25
Unclassified HIGH 7.5
CVE-2026-2416

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is du…

Mitigation only
Fix from $1,950 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3164

A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The m…

Mitigation only
Fix from $2,300 2026-02-25
College Management System CRITICAL 9.8
CVE-2026-3151

A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The…

Mitigation only
Fix from $2,300 2026-02-25
College Management System CRITICAL 9.8
CVE-2026-3152

A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php…

Mitigation only
Fix from $2,300 2026-02-25
Document Management System CRITICAL 9.8
CVE-2026-3153

A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipu…

Mitigation only
Fix from $2,300 2026-02-25
College Management System HIGH 8.8
CVE-2026-3150

A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-tea…

No fix yet
Fix from $1,950 2026-02-25
College Management System HIGH 8.8
CVE-2026-3149

A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown functionality of the file /admin…

No fix yet
Fix from $1,950 2026-02-25
Simple And Nice Shopping Cart Script CRITICAL 9.8
CVE-2026-3148

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. …

Mitigation only
Fix from $2,300 2026-02-25
Interface Traduction Objets HIGH 8.8
CVE-2026-27747

The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_obje…

Fix: 2.2.2+
Fix from $1,950 2026-02-25
Referer Spam CRITICAL 9.8
CVE-2026-27743

The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_s…

Fix: 1.3.0+
Fix from $2,300 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3135

A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.p…

Mitigation only
Fix from $2,300 2026-02-25
Document Management System CRITICAL 9.8
CVE-2026-3133

A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of …

Mitigation only
Fix from $2,300 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3134

A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admi…

Mitigation only
Fix from $2,300 2026-02-25
Masterscada CRITICAL 9.8
CVE-2026-21410

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potenti…

Mitigation only
Fix from $2,300 2026-02-24
Mautic HIGH 8.8
CVE-2026-3105

SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in th…

Fix: 4.4.19 / 5.2.10+
Fix from $1,950 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23969

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within…

Fix: 4.1.2+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23980

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user wit…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Dotcms CRITICAL 9.9
CVE-2025-11165

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp…

Fix: 24.12.27 / 25.07.10+
Fix from $2,300 2026-02-24
Document Management System CRITICAL 9.8
CVE-2026-3069

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. …

Mitigation only
Fix from $2,300 2026-02-24
Document Management System CRITICAL 9.8
CVE-2026-3068

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a…

Mitigation only
Fix from $2,300 2026-02-24
Pearprojectapi CRITICAL 9.8
CVE-2026-3057

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/co…

Fix: after 2.8.10
Fix from $2,300 2026-02-24
Ormar HIGH 7.5
CVE-2026-26198

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by pa…

Fix: 0.23.0+
Fix from $1,950 2026-02-24
E Logbook With Health Monitoring System For Covid 19 CRITICAL 9.8
CVE-2026-3046

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unkno…

Mitigation only
Fix from $2,300 2026-02-24
Event Management System CRITICAL 9.8
CVE-2026-3042

A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. P…

Mitigation only
Fix from $2,300 2026-02-24
Unclassified CRITICAL 9.3
CVE-2025-41002

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the dat…

Mitigation only
Fix from $2,300 2026-02-23