Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.3
CVE-2026-2247

SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote a…

Mitigation only
Fix from $1,950 2026-02-17
Unclassified MEDIUM 6.3
CVE-2026-2553

A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown pa…

Mitigation only
Fix from $1,600 2026-02-16
Unclassified HIGH 7.5
CVE-2026-2024

The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due…

Mitigation only
Fix from $1,950 2026-02-14
Unclassified CRITICAL 9.8
CVE-2025-69633

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7…

Mitigation only
Fix from $2,300 2026-02-13
Unclassified HIGH 7.5
CVE-2019-25335

PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers c…

No fix yet
Fix from $1,950 2026-02-12
Unclassified HIGH 8.2
CVE-2019-25325

Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authenti…

No fix yet
Fix from $1,950 2026-02-12
Unclassified MEDIUM 6.5
CVE-2019-25320

E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by mani…

No fix yet
Fix from $1,600 2026-02-12
Password Management Application HIGH 7.5
CVE-2019-25346

TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Atta…

No fix yet
Fix from $1,950 2026-02-12
Password Management Application HIGH 7.5
CVE-2019-25347

thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attac…

No fix yet
Fix from $1,950 2026-02-12
More Reporting MEDIUM 6.5
CVE-2026-22821

mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.

Fix: 1.9.4+
Fix from $1,600 2026-02-12
Cordys Crm CRITICAL 9.8
CVE-2025-70981

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

Mitigation only
Fix from $2,300 2026-02-12
E Commerce Package CRITICAL 9.8
CVE-2025-10969

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Com…

Fix: after 2025-11-27
Fix from $2,300 2026-02-12
Unclassified MEDIUM 6.5
CVE-2025-13431

The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-02-11
Worklenz HIGH 8.8
CVE-2026-25947

Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construc…

Fix: 2.1.7+
Fix from $1,950 2026-02-10
Evershop CRITICAL 9.8
CVE-2026-25993

EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path val…

Fix: after 2.1.0
Fix from $2,300 2026-02-10
Endpoint Manager MEDIUM 6.5
CVE-2026-1602

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2026-02-10
Unclassified HIGH 8.8
CVE-2025-7636

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security Systems Computer Industry and …

Mitigation only
Fix from $1,950 2026-02-10
Unclassified HIGH 7.5
CVE-2026-2093

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read …

Mitigation only
Fix from $1,950 2026-02-10
Unclassified HIGH 8.8
CVE-2026-2094

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, m…

Mitigation only
Fix from $1,950 2026-02-10
Craft Cms HIGH 8.8
CVE-2026-25495

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/g…

Fix: 4.16.18 / 5.8.22+
Fix from $1,950 2026-02-09
Unclassified CRITICAL 9.8
CVE-2025-6830

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Passw…

Mitigation only
Fix from $2,300 2026-02-09
News Portal Project CRITICAL 9.8
CVE-2026-2225

A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component …

Mitigation only
Fix from $2,300 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2223

A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the f…

Mitigation only
Fix from $2,300 2026-02-09
Unclassified MEDIUM 6.5
CVE-2026-2235

C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read databa…

Mitigation only
Fix from $1,600 2026-02-09
Unclassified HIGH 7.5
CVE-2026-2236

C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read dat…

Mitigation only
Fix from $1,950 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2220

A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assess…

Mitigation only
Fix from $2,300 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2221

A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the …

Mitigation only
Fix from $2,300 2026-02-09
Event Management System CRITICAL 9.8
CVE-2026-2217

A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php…

Mitigation only
Fix from $2,300 2026-02-09
Online Music Site CRITICAL 9.8
CVE-2026-2211

A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCate…

Mitigation only
Fix from $2,300 2026-02-09
Online Music Site CRITICAL 9.8
CVE-2026-2212

A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Admini…

Mitigation only
Fix from $2,300 2026-02-09