Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Document Management System CRITICAL 9.8
CVE-2026-3068

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a…

Mitigation only
Fix from $2,300 2026-02-24
Pearprojectapi CRITICAL 9.8
CVE-2026-3057

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/co…

Fix: after 2.8.10
Fix from $2,300 2026-02-24
Ormar HIGH 7.5
CVE-2026-26198

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by pa…

Fix: 0.23.0+
Fix from $1,950 2026-02-24
E Logbook With Health Monitoring System For Covid 19 CRITICAL 9.8
CVE-2026-3046

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unkno…

Mitigation only
Fix from $2,300 2026-02-24
Event Management System CRITICAL 9.8
CVE-2026-3042

A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. P…

Mitigation only
Fix from $2,300 2026-02-24
Unclassified CRITICAL 9.3
CVE-2025-41002

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the dat…

Mitigation only
Fix from $2,300 2026-02-23
Unclassified HIGH 8.3
CVE-2026-1367EPSS 7%

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

Mitigation only
Fix from $1,950 2026-02-23
Unclassified CRITICAL 9.8
CVE-2026-24494

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attack…

Mitigation only
Fix from $2,300 2026-02-23
Unclassified MEDIUM 6.3
CVE-2026-2963

A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C6/Jhsoft.Web.officesupply/Off…

Mitigation only
Fix from $1,600 2026-02-23
Platinum E Ticaret HIGH 7.5
CVE-2019-25461

Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injec…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25462

Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL…

No fix yet
Fix from $1,950 2026-02-22
Emlak CRITICAL 9.1
CVE-2019-25456

Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $2,300 2026-02-22
Firma HIGH 7.5
CVE-2019-25457

Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL cod…

No fix yet
Fix from $1,950 2026-02-22
Firma Rehberi CRITICAL 9.8
CVE-2019-25458

Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting …

Mitigation only
Fix from $2,300 2026-02-22
Emlak CRITICAL 9.8
CVE-2019-25459

Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database querie…

Mitigation only
Fix from $2,300 2026-02-22
Platinum E Ticaret HIGH 7.5
CVE-2019-25460

Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injec…

No fix yet
Fix from $1,950 2026-02-22
E Ticaret HIGH 7.5
CVE-2019-25455

Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL …

No fix yet
Fix from $1,950 2026-02-22
Dolibarr Erp\/crm HIGH 7.5
CVE-2019-25452

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated …

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25440

WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro…

No fix yet
Fix from $1,950 2026-02-22
Web Wiz Forums HIGH 7.5
CVE-2019-25442

Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25443

Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25446

DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $1,950 2026-02-22
Dolibarr Erp\/crm HIGH 7.5
CVE-2019-25450

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25391

Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25433

XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25439

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code throu…

No fix yet
Fix from $1,950 2026-02-22
Unclassified HIGH 8.2
CVE-2019-25366

microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mali…

No fix yet
Fix from $1,950 2026-02-22
Online Reviewer System CRITICAL 9.8
CVE-2026-2912

A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessment…

Mitigation only
Fix from $2,300 2026-02-22
Vehicle Management System CRITICAL 9.8
CVE-2026-2867

A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing …

Mitigation only
Fix from $2,300 2026-02-21
Zoneminder HIGH 8.8
CVE-2026-27470

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is …

Fix: 1.36.38 / 1.38.1+
Fix from $1,950 2026-02-21