Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.8
CVE-2026-70370

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directl…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-70371

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the …

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-14872

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before usin…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18719

A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a man…

No fix yet
Fix from $1,600 2026-08-04
Campaign CRITICAL 9.9
CVE-2026-48326

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Campaign CRITICAL 10.0
CVE-2026-48330

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-69240

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function define…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-51775

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.1
CVE-2026-52521

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the Comment…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-18737

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an un…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.8
CVE-2026-41453

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to injec…

Mitigation only
Fix from $1,950 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69083

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69084

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69085

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is …

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.6
CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthen…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-16532

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified HIGH 8.1
CVE-2026-16539

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-12965

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, a…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-65321

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper …

No fix yet
Fix from $2,300 2026-08-02
Unclassified HIGH 8.2
CVE-2026-14920

## Summary

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-6453

The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient inpu…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-16087

The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Par…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-15018

The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versio…

No fix yet
Fix from $1,600 2026-08-01
Unclassified CRITICAL 9.1
CVE-2026-13596

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL qu…

Mitigation only
Fix from $2,300 2026-08-01
Unclassified MEDIUM 5.5
CVE-2026-45376

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organ…

No fix yet
Fix from $1,600 2026-07-31
Unclassified CRITICAL 9.8
CVE-2025-69948

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2025-69946

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.4
CVE-2026-58048

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

No fix yet
Fix from $2,300 2026-07-31
Pgadmin 4 CRITICAL 9.0
CVE-2026-17351

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlpar…

Fix: 9.17+
Fix from $2,300 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-17346

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but miss…

Fix: 9.17+
Fix from $1,950 2026-07-31