Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.2 CVE-2019-25728 Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the… No fix yet Fix from $1,9502026-06-04 HIGH 8.2 CVE-2019-25730 Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici… No fix yet Fix from $1,9502026-06-04 HIGH 8.2 CVE-2019-25726 All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj… No fix yet Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-4104 Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allo… Mitigation only Fix from $2,3002026-06-04 HIGH 7.6 CVE-2026-49771 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL I… Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.5 CVE-2026-8653 The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and inclu… Mitigation only Fix from $1,6002026-06-04 HIGH 7.6 CVE-2025-15655 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection… Mitigation only Fix from $1,9502026-06-03 HIGH 7.3 CVE-2026-10704 A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin… Mitigation only Fix from $1,9502026-06-03 HIGH 7.3 CVE-2026-10620 A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the… Mitigation only Fix from $1,9502026-06-02 HIGH 7.5 CVE-2026-5073 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action i… Mitigation only Fix from $1,9502026-06-02 MEDIUM 6.5 CVE-2026-5074 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action… Mitigation only Fix from $1,6002026-06-02 HIGH 7.3 CVE-2026-10607 A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipul… Mitigation only Fix from $1,9502026-06-02 HIGH 7.3 CVE-2026-10608 A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of th… Mitigation only Fix from $1,9502026-06-02 HIGH 7.3 CVE-2026-10606 A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedba… Mitigation only Fix from $1,9502026-06-02 CRITICAL 9.3 CVE-2026-42684 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.… Mitigation only Fix from $2,3002026-06-02 MEDIUM 6.3 CVE-2026-10568 A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipul… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.3 CVE-2026-10302 A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing … Mitigation only Fix from $1,6002026-06-02 HIGH 8.8 CVE-2026-24782 Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be explo… Kiteworks 9.3.0+ Fix from $1,9502026-06-01 CRITICAL 9.8 CVE-2026-25879 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM… Mitigation only Fix from $2,3002026-06-01 MEDIUM 6.3 CVE-2026-10296 A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10297 A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulat… Mitigation only Fix from $1,6002026-06-01 HIGH 8.2 CVE-2026-49491 Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the … Mitigation only Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10290 A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tou… Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.9 CVE-2026-0075 In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privile… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.1 CVE-2018-25429 Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious c… No fix yet Fix from $1,9502026-06-01 HIGH 7.1 CVE-2018-25430 Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious c… No fix yet Fix from $1,9502026-06-01 HIGH 7.1 CVE-2018-25431 No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attack… No fix yet Fix from $1,9502026-06-01 HIGH 8.2 CVE-2018-25433 Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information b… No fix yet Fix from $1,9502026-06-01 HIGH 8.2 CVE-2018-25434 WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malic… No fix yet Fix from $1,9502026-06-01 HIGH 8.2 CVE-2018-25428 Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious… No fix yet Fix from $1,9502026-06-01