Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.3 CVE-2026-19972 A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewpatient.php. Such man… Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.3 CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specificat… No fix yet Fix from $5,7502026-08-16 HIGH 7.2 CVE-2026-2497 The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all version… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-9767 The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19934 A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manip… No fix yet Fix from $4,0002026-08-16 HIGH 7.2 CVE-2026-18653 The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrato… Fix unknown Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-15963 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz … No fix yet Fix from $4,0002026-08-16 MEDIUM 6.5 CVE-2026-16079 The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and i… No fix yet Fix from $4,0002026-08-16 HIGH 7.3 CVE-2026-19926 A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-ga… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.3 CVE-2026-19923 A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing… No fix yet Fix from $4,0002026-08-16 HIGH 7.3 CVE-2026-19919 A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.3 CVE-2026-19920 A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulatio… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19921 A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /h… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19917 A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. … No fix yet Fix from $4,0002026-08-15 HIGH 7.3 CVE-2026-19905 A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx… No fix yet Fix from $4,9002026-08-15 HIGH 7.3 CVE-2026-19899 A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit… No fix yet Fix from $4,9002026-08-15 MEDIUM 6.3 CVE-2026-19894 A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewmedicine.php. Pe… No fix yet Fix from $4,0002026-08-15 MEDIUM 6.5 CVE-2026-12248 The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all versions up to, and including, 4.9.5… No fix yet Fix from $4,0002026-08-15 HIGH 7.1 CVE-2026-16007 AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to… No fix yet Fix from $4,9002026-08-15 MEDIUM 6.5 CVE-2026-18387 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'tag_query' parameter… No fix yet Fix from $4,0002026-08-15 MEDIUM 6.5 CVE-2026-16586 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via Mul… No fix yet Fix from $4,0002026-08-15 MEDIUM 5.3 CVE-2026-15993 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}'… No fix yet Fix from $4,0002026-08-15 MEDIUM 6.5 CVE-2026-15453 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in… No fix yet Fix from $4,0002026-08-15 MEDIUM 6.5 CVE-2026-16080 The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and … No fix yet Fix from $4,0002026-08-15 HIGH 7.5 CVE-2026-15162 The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-s… No fix yet Fix from $4,9002026-08-15 HIGH 8.6 CVE-2026-71571 Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permi… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.2 CVE-2026-67365 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (… No fix yet Fix from $5,7502026-08-14 MEDIUM 5.4 CVE-2026-17227 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of … No fix yet Fix from $4,0002026-08-14 MEDIUM 6.0 CVE-2026-18403 LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that cop… No fix yet Fix from $4,0002026-08-14 HIGH 8.6 CVE-2026-73850 Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.ph… No fix yet Fix from $4,9002026-08-14