Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-38158 A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform… No fix yet Fix from $2,3002026-07-16 HIGH 8.8 CVE-2025-45868 LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to ma… No fix yet Fix from $1,9502026-07-16 HIGH 8.7 CVE-2026-58078 Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vu… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-15022 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-13754 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, a… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-13767 The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-12395 The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authentic… No fix yet Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-12753 The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' p… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-12941 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'orde… No fix yet Fix from $1,6002026-07-16 HIGH 7.3 CVE-2026-15907 A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Exe… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.5 CVE-2026-62361 listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects t… Patch available Fix from $1,6002026-07-15 CRITICAL 10.0 CVE-2026-52887 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/… Patch available Fix from $2,3002026-07-15 HIGH 7.1 CVE-2026-50030 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlC… Patch available Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-45535 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable … Patch available Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-45320 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed b… Patch available Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-45417 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configura… Patch available Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-56287 A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-57821 A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-35152 A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-57831 Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulne… Mitigation only Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-57832 Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthe… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-15804 The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, ther… Mitigation only Fix from $1,9502026-07-15 HIGH 8.6 CVE-2026-12512 The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowi… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.9 CVE-2026-11851 Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models al… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.1 CVE-2026-48324 ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … Coldfusion Mitigation only Fix from $2,3002026-07-14 HIGH 7.2 CVE-2026-47992EPSS 20% Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result… Commerce 1.21.0+ Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-45073 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAda… Symfony 5.4.52 / 6.4.40+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-47295 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-47296 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-15703 A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/u… Mitigation only Fix from $1,9502026-07-14