Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-39948 Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the … Cacti 1.2.31+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-39955 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI… Cacti 1.2.31+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-39893 Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into … Cacti 1.2.31+ Fix from $2,3002026-06-24 CRITICAL 9.6 CVE-2026-56351 n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inje… N8n 2.4.0+ Fix from $2,3002026-06-24 HIGH 8.8 CVE-2025-71332 Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an … Flowise after 2.2.7 Fix from $1,9502026-06-24 HIGH 7.6 CVE-2026-56052 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Bl… Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-9179 The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in… Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-8705 The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX… No fix yet Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-47384 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL int… Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.0 CVE-2026-47375 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed b… Mitigation only Fix from $1,6002026-06-23 HIGH 7.5 CVE-2025-61024 An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQ… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61029 An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL stat… No fix yet Fix from $1,9502026-06-23 CRITICAL 9.0 CVE-2026-44792 n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connec… N8n 1.123.43 / 2.20.7+ Fix from $2,3002026-06-23 HIGH 8.3 CVE-2026-34914 A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the cli… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61020 An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted … Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61021 An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craf… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61022 An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted S… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61023 An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL stat… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61025 An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61027 An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL stat… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61028 An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61018 An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted S… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2025-61019 An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted … Mitigation only Fix from $1,9502026-06-23 HIGH 7.7 CVE-2026-54313 n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter … N8n 2.24.0+ Fix from $1,9502026-06-23 CRITICAL 9.9 CVE-2026-54310 n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows c… N8n 2.25.7 / 2.26.2+ Fix from $2,3002026-06-23 MEDIUM 6.5 CVE-2026-52673 SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-56221 Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are inte… Mitigation only Fix from $1,6002026-06-22 HIGH 8.8 CVE-2026-44271 Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Inj… Wyse Management Suite 2605+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-44272 Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Inj… Wyse Management Suite 2605+ Fix from $1,9502026-06-22 MEDIUM 6.0 CVE-2026-7253 IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL stateme… Watson Speech Services Cartridge 5.3.1+ Fix from $1,6002026-06-22