Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2026-56062 Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. Mitigation only Fix from $2,3002026-06-26 HIGH 8.5 CVE-2026-56064 Subscriber SQL Injection in Tourfic <= 2.22.5 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.3 CVE-2026-56034 Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56036 Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54825 Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54827 Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54831 Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54820 Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. Mitigation only Fix from $2,3002026-06-26 MEDIUM 6.5 CVE-2026-13226 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in … Mitigation only Fix from $1,6002026-06-26 HIGH 7.2 CVE-2026-40083 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+impl… Cacti 1.2.31+ Fix from $1,9502026-06-25 HIGH 7.7 CVE-2026-37149 GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in… Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-57587 A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malic… Nessus 10.12.1+ Fix from $1,6002026-06-25 CRITICAL 9.3 CVE-2026-54849 Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54843 Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. Mitigation only Fix from $2,3002026-06-25 HIGH 7.5 CVE-2026-54829 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows B… Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.3 CVE-2026-54836 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue af… Mitigation only Fix from $2,3002026-06-25 HIGH 8.5 CVE-2026-54838 Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 8.5 CVE-2026-54822 Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-12937 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via … Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-2508 The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and incl… Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-12077 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to,… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-12079 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 … Mitigation only Fix from $1,6002026-06-25 HIGH 8.8 CVE-2026-9781 Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-9782 Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-9783 Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-9784 Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-9785 Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-9786 Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-39951 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph… Cacti 1.2.31+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-7570 Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Netvault Backup 14.0.2+ Fix from $1,9502026-06-25