Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.3 CVE-2026-15490 A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknow… Mitigation only Fix from $1,9502026-07-12 HIGH 7.3 CVE-2026-15489 A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unkno… Mitigation only Fix from $1,9502026-07-12 HIGH 7.3 CVE-2026-15482 A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?… Mitigation only Fix from $1,9502026-07-12 MEDIUM 6.3 CVE-2026-15477 A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/s… Mitigation only Fix from $1,6002026-07-12 MEDIUM 6.3 CVE-2026-15478 A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php… Mitigation only Fix from $1,6002026-07-12 CRITICAL 9.8 CVE-2026-60090 PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() … Patch available Fix from $2,3002026-07-11 HIGH 7.5 CVE-2026-4661 The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname… No fix yet Fix from $1,9502026-07-11 HIGH 7.5 CVE-2026-15335 The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and inclu… Mitigation only Fix from $1,9502026-07-11 MEDIUM 6.5 CVE-2026-15073 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.5 CVE-2026-15072 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.5 CVE-2026-13262 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val'… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.5 CVE-2026-13242 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. … Geolocation Field 3.15.0+ Fix from $1,6002026-07-10 HIGH 7.4 CVE-2026-15081 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. … Location Selector 1.3+ Fix from $1,9502026-07-10 MEDIUM 5.4 CVE-2026-57230 OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy ena… Patch available Fix from $1,6002026-07-10 HIGH 7.6 CVE-2026-55405 LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26… Patch available Fix from $1,9502026-07-10 MEDIUM 6.4 CVE-2026-11321 The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, wi… Mitigation only Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-5801 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt… Mitigation only Fix from $2,3002026-07-10 HIGH 8.8 CVE-2026-61461 Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by s… Dify 1.16.0+ Fix from $1,9502026-07-10 HIGH 7.2 CVE-2026-53448 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters direc… Coturn 4.12.0+ Fix from $1,9502026-07-10 CRITICAL 9.8 CVE-2026-2397 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows… Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.2 CVE-2026-58492 grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a… Patch available Fix from $2,3002026-07-10 HIGH 7.7 CVE-2026-56689 Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') … Powerflex Manager 4.5.5.2 / 5.1.0.1+ Fix from $1,9502026-07-10 HIGH 8.5 CVE-2026-56690 Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') … Powerflex Manager 4.5.5.2 / 5.1.0.1+ Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-13010 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortco… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-15104 The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the … Mitigation only Fix from $1,6002026-07-10 CRITICAL 9.1 CVE-2026-15300 The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, … Mitigation only Fix from $2,3002026-07-10 MEDIUM 5.9 CVE-2026-15289 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in al… Mitigation only Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-15290 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-15287 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all ve… Mitigation only Fix from $1,6002026-07-10 HIGH 8.7 CVE-2026-50180 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_valid… Patch available Fix from $1,9502026-07-10