Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2026-54760 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation,… Mitigation only Fix from $2,3002026-07-10 HIGH 7.5 CVE-2026-59834 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concate… Patch available Fix from $1,9502026-07-09 HIGH 7.7 CVE-2026-55208 Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin p… Patch available Fix from $1,9502026-07-09 HIGH 7.3 CVE-2026-15190 A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Perform… Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-56292 Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joom… Acymailing 10.11.1+ Fix from $1,9502026-07-09 HIGH 8.6 CVE-2026-50644 SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands int… Mitigation only Fix from $1,9502026-07-09 CRITICAL 9.8 CVE-2026-5955 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticare… Mitigation only Fix from $2,3002026-07-09 MEDIUM 6.5 CVE-2026-13011 The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection… Mitigation only Fix from $1,6002026-07-09 HIGH 7.3 CVE-2026-15135 A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The… Mitigation only Fix from $1,9502026-07-09 HIGH 7.3 CVE-2026-15137 A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\Vie… Mitigation only Fix from $1,9502026-07-09 HIGH 7.3 CVE-2026-15134 A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of … Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-39178 A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the al… Patch available Fix from $1,6002026-07-08 MEDIUM 6.3 CVE-2026-39179 A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in t… Patch available Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-9074 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset… Api Connect 10.0.8.10 / 12.1.1.0+ Fix from $2,3002026-07-08 CRITICAL 9.6 CVE-2026-15062 SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege… Mitigation only Fix from $2,3002026-07-08 HIGH 8.8 CVE-2026-15067 Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data sourc… Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-59257 n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery op… N8n 1.123.61 / 2.27.4+ Fix from $1,9502026-07-08 CRITICAL 9.8 CVE-2026-8307 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Inje… Mitigation only Fix from $2,3002026-07-08 HIGH 7.5 CVE-2026-6854 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all ve… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-6230 The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.… Patch available Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-9700 The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due t… Mitigation only Fix from $1,9502026-07-08 HIGH 8.7 CVE-2026-55635 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter va… Patch available Fix from $1,9502026-07-07 MEDIUM 6.9 CVE-2026-33734 FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Mass… Mitigation only Fix from $1,6002026-07-06 HIGH 8.1 CVE-2026-14471 Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13… Mitigation only Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-14809 Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL com… Mitigation only Fix from $1,9502026-07-06 MEDIUM 6.3 CVE-2026-14797 A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-v… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14798 A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartmen… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14799 A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishl… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14795 A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14796 A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.ph… Mitigation only Fix from $1,6002026-07-06