Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.5 CVE-2026-65451 Contributor SQL Injection in MapSVG <= 8.14.0 versions. No fix yet Fix from $1,9502026-07-23 HIGH 8.5 CVE-2026-65454 Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. No fix yet Fix from $1,9502026-07-23 CRITICAL 9.3 CVE-2026-61948 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-61949 Unauthenticated SQL Injection in Bookly <= 27.7 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-61950 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-59514 Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-59525 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-59526 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. No fix yet Fix from $2,3002026-07-23 HIGH 8.5 CVE-2026-25405 Contributor SQL Injection in eRoom <= 1.7.1 versions. No fix yet Fix from $1,9502026-07-23 HIGH 8.5 CVE-2026-24552 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL I… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-15761 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all ver… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-15906 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-15448 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-13119 The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by th… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-13009 The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, a… No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-9713 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded c… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-2395 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Co… No fix yet Fix from $2,3002026-07-22 HIGH 7.5 CVE-2026-12987 The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a boo… No fix yet Fix from $1,9502026-07-22 MEDIUM 6.3 CVE-2026-16490 A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. Th… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.3 CVE-2026-62527 Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affec… Learning Management No fix yet Fix from $1,6002026-07-21 MEDIUM 6.3 CVE-2026-62528 Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that are affecte… Human Capital Management Configuration Workbench No fix yet Fix from $1,6002026-07-21 HIGH 8.8 CVE-2026-62516 Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are aff… Demantra Demand Management after 12.2.15 Fix from $1,9502026-07-21 MEDIUM 6.3 CVE-2026-61294 Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versio… Common Applications Calendar No fix yet Fix from $1,6002026-07-21 MEDIUM 6.3 CVE-2026-61266 Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization). Supported versio… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 HIGH 8.3 CVE-2026-60582 Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is… Enterprise Command Center Framework No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16484 A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-52476 SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the Datacenter… No fix yet Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-63080 Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read ev… No fix yet Fix from $1,6002026-07-21 CRITICAL 9.8 CVE-2026-52469 SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file No fix yet Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-52470 SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file Mitigation only Fix from $2,3002026-07-21