Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-48528 Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth… No fix yet Fix from $5,7502026-08-14 HIGH 7.1 CVE-2026-19680 A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19825 A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the … No fix yet Fix from $4,9002026-08-14 CRITICAL 10.0 CVE-2026-72811 SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates s… No fix yet Fix from $5,7502026-08-14 MEDIUM 6.5 CVE-2026-16810 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Inje… No fix yet Fix from $4,0002026-08-14 HIGH 8.6 CVE-2026-15205 The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query withi… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.3 CVE-2026-19785 A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/inclu… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19767 A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimin… No fix yet Fix from $4,0002026-08-14 HIGH 7.3 CVE-2026-19764 A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the fi… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.3 CVE-2026-73663 FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted … No fix yet Fix from $5,7502026-08-13 HIGH 7.6 CVE-2026-73408 Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an … No fix yet Fix from $4,9002026-08-13 CRITICAL 10.0 CVE-2026-72851 Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers c… No fix yet Fix from $5,7502026-08-13 HIGH 7.6 CVE-2026-72853 Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table n… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-16961 IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker … I No fix yet Fix from $5,7502026-08-13 HIGH 7.5 CVE-2024-58374 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attacke… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2019-25765 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL b… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-59109 SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a rece… No fix yet Fix from $4,9002026-08-13 HIGH 7.2 CVE-2026-73670 A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a… No fix yet Fix from $4,9002026-08-13 HIGH 7.3 CVE-2026-19710 A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $4,9002026-08-13 HIGH 7.6 CVE-2026-73346 Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.5 CVE-2026-66658 Subscriber SQL Injection in Reviewer <= 3.14.2 versions. No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-66472 Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-66478 Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-66458 Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-66436 Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-66446 Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. No fix yet Fix from $5,7502026-08-13 HIGH 8.5 CVE-2026-66430 Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-61969 Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-61966 Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. No fix yet Fix from $5,7502026-08-13 HIGH 8.5 CVE-2026-28184 Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. No fix yet Fix from $4,9002026-08-13