Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.9 CVE-2026-50747 A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi … Unifi Talk Application 5.2.2+ Fix from $2,3002026-07-02 HIGH 8.5 CVE-2026-57765 Contributor SQL Injection in WP EasyCart <= 5.9.0 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 8.5 CVE-2026-57752 Contributor SQL Injection in iNET Webkit 1.2.4 versions. No fix yet Fix from $1,9502026-07-02 HIGH 8.5 CVE-2026-57756 Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions. Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.3 CVE-2026-57683 Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. Mitigation only Fix from $2,3002026-07-02 HIGH 8.5 CVE-2026-57687 Contributor SQL Injection in Custom Field Template <= 2.7.8 versions. Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.3 CVE-2026-57679 Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. No fix yet Fix from $2,3002026-07-02 HIGH 8.5 CVE-2025-69094 Subscriber SQL Injection in Unicamp <= 2.2.2 versions. Mitigation only Fix from $1,9502026-07-02 MEDIUM 6.5 CVE-2026-14029 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in… Mitigation only Fix from $1,6002026-07-02 HIGH 7.5 CVE-2026-8441 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action i… Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.8 CVE-2026-52186 SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc c… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-14363 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte… Cargo 3.9.1+ Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58521 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte… Cargo 3.9.1+ Fix from $2,3002026-07-01 MEDIUM 6.5 CVE-2026-51946 SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive in… Mitigation only Fix from $1,6002026-07-01 CRITICAL 9.8 CVE-2026-34101 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extensio… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34102 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where i… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34103 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extensio… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34104 Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34105 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, ext… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34099 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = … Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34100 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, t… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-57517 Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQ… Mitigation only Fix from $2,3002026-07-01 MEDIUM 6.5 CVE-2026-13454 The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and includ… Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-11823 The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-12110 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'ta… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-12090 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wp… Mitigation only Fix from $1,6002026-07-01 CRITICAL 9.3 CVE-2026-55721 Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie valu… Mitigation only Fix from $2,3002026-06-30 MEDIUM 5.5 CVE-2026-3602 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is v… App Connect Enterprise 12.0.12.27 / 13.0.8.0+ Fix from $1,6002026-06-30 HIGH 7.6 CVE-2026-58376 Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary … Patch available Fix from $1,9502026-06-30 MEDIUM 5.4 CVE-2025-53648 SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to… Gravitino 1.0.0+ Fix from $1,6002026-06-30