Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.2 CVE-2026-54348 Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75876 A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of t… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-47720 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString functio… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-74015 Unauthenticated SQL Injection in Readabler < 2.0.18 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.3 CVE-2026-73392 Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.3 CVE-2026-73365 Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. Fix unknown Fix from $5,7502026-08-18 HIGH 7.1 CVE-2026-73345 Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.3 CVE-2026-73355 Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.3 CVE-2026-73339 Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.3 CVE-2026-73187 Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. Fix unknown Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-66622 Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 8.5 CVE-2026-32466 Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.3 CVE-2026-75778 A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of th… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75088 A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi… Fix unknown Fix from $4,0002026-08-18 HIGH 7.3 CVE-2026-75089 A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75086 A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-75087 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin… Fix unknown Fix from $4,0002026-08-18 HIGH 7.3 CVE-2026-75079 A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_sub… Fix unknown Fix from $4,9002026-08-18 HIGH 7.3 CVE-2026-75080 A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-67854 SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67917 zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma… Fix unknown Fix from $5,7502026-08-17 HIGH 8.4 CVE-2026-64657 Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts i… Fix unknown Fix from $4,9002026-08-17 HIGH 7.6 CVE-2026-65822 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactiv… Fix unknown Fix from $4,9002026-08-17 HIGH 7.3 CVE-2026-75014 A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.3 CVE-2026-74254 Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection iss… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-51346 SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensit… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50769 The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conf… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.3 CVE-2026-20000 A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptio… Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.4 CVE-2026-15623 A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Clou… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.3 CVE-2026-19973 A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /vie… Fix unknown Fix from $4,0002026-08-17