Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-39196 Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition f… Mitigation only Fix from $2,3002026-06-15 HIGH 8.8 CVE-2026-36670 A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows a… Mitigation only Fix from $1,9502026-06-15 HIGH 7.1 CVE-2019-25746 WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database quer… No fix yet Fix from $1,9502026-06-15 HIGH 8.2 CVE-2016-20071 The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to … No fix yet Fix from $1,9502026-06-15 HIGH 8.2 CVE-2016-20072 BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL que… No fix yet Fix from $1,9502026-06-15 HIGH 8.2 CVE-2016-20073 Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu… No fix yet Fix from $1,9502026-06-15 HIGH 8.2 CVE-2016-20068 WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to … No fix yet Fix from $1,9502026-06-15 HIGH 8.2 CVE-2016-20069 WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to … No fix yet Fix from $1,9502026-06-15 MEDIUM 6.3 CVE-2026-12206 A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/… Mitigation only Fix from $1,6002026-06-15 MEDIUM 6.3 CVE-2026-12188 A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/c… Mitigation only Fix from $1,6002026-06-14 HIGH 7.6 CVE-2026-6428 SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x befor… Mitigation only Fix from $1,9502026-06-13 HIGH 7.5 CVE-2026-9848 The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.… Mitigation only Fix from $1,9502026-06-13 MEDIUM 6.3 CVE-2026-12131 A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \applic… Mitigation only Fix from $1,6002026-06-12 CRITICAL 9.1 CVE-2026-44172 MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, … MariaDB Mitigation only Fix from $2,3002026-06-12 MEDIUM 6.9 CVE-2026-41581 Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This i… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.9 CVE-2026-48613 SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing … Mitigation only Fix from $1,6002026-06-12 CRITICAL 9.8 CVE-2026-45060 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind… Mitigation only Fix from $2,3002026-06-11 HIGH 8.8 CVE-2026-45418 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple … Mitigation only Fix from $1,9502026-06-11 CRITICAL 9.3 CVE-2026-39494 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind … Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.3 CVE-2026-42647 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. … Mitigation only Fix from $2,3002026-06-11 HIGH 7.5 CVE-2026-11945 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code… Postgresql Anonymizer 3.1.1+ Fix from $1,9502026-06-11 CRITICAL 9.8 CVE-2026-38581 SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFor… Mitigation only Fix from $2,3002026-06-11 MEDIUM 6.5 CVE-2026-53474 A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xls… Migration Assessment 0.13.5+ Fix from $1,6002026-06-10 HIGH 8.8 CVE-2026-52758 Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries withou… Ghidra 12.1+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-49498 Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double… Ghidra 12.1+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-3018 The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and inclu… Mitigation only Fix from $1,9502026-06-10 HIGH 8.6 CVE-2026-3326 The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action avail… Mitigation only Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-50636 The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), w… Patch available Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-8025 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-7486 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injectio… Mitigation only Fix from $2,3002026-06-09