Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-67403 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2025-67404 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla… No fix yet Fix from $2,3002026-07-29 HIGH 7.3 CVE-2025-67405 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-67406 https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). T… No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-67407 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-67408 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2025-69942 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2025-69943 kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. Mitigation only Fix from $2,3002026-07-29 HIGH 7.3 CVE-2025-69944 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2025-65340 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. No fix yet Fix from $2,3002026-07-29 HIGH 8.8 CVE-2026-5490 DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio… No fix yet Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-8339 A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authentica… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.1 CVE-2026-51992 SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries … Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL… Gridbox 2.20.2+ Fix from $2,3002026-07-29 MEDIUM 5.1 CVE-2026-33385 A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip… No fix yet Fix from $1,6002026-07-29 HIGH 7.1 CVE-2026-12895 SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interp… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.1 CVE-2026-63229 A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO … Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-63230 A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, … No fix yet Fix from $2,3002026-07-29 HIGH 8.1 CVE-2026-63231 A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-f… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.9 CVE-2026-63232 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcem… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2026-63233 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall an… Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2026-63234 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessmen… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-54658 Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.4 CVE-2026-6881 A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive … Mitigation only Fix from $2,3002026-07-28 MEDIUM 6.3 CVE-2026-11391 Tanium addressed a SQL injection vulnerability in Patch. No fix yet Fix from $1,6002026-07-28 HIGH 8.1 CVE-2026-7769 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0… Sterling B2b Integrator after 6.2.2.0_1 Fix from $1,9502026-07-28 CRITICAL 9.0 CVE-2026-50736 The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads… No fix yet Fix from $2,3002026-07-28 MEDIUM 6.5 CVE-2026-15304 The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4.… No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-14785 The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1… No fix yet Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-16462 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL comm… No fix yet Fix from $2,3002026-07-28