Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.2 CVE-2018-25398 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25399 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25400 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25401 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25402 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25389 HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25390 HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu… No fix yet Fix from $1,9502026-05-29 HIGH 7.1 CVE-2018-25392 MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25394 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25395 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25382 Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code throug… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25385 E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj… No fix yet Fix from $1,9502026-05-29 HIGH 8.2 CVE-2018-25386 HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL … No fix yet Fix from $1,9502026-05-29 HIGH 8.8 CVE-2026-44238 FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST para… Freepbx 16.0.50 / 17.0.11+ Fix from $1,9502026-05-29 HIGH 7.1 CVE-2026-4776 An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query paramet… Mitigation only Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2026-45288 Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-suppl… Patch available Fix from $2,3002026-05-28 MEDIUM 6.5 CVE-2026-7048 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' pa… Mitigation only Fix from $1,6002026-05-28 HIGH 7.5 CVE-2026-7797 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection v… Mitigation only Fix from $1,9502026-05-28 HIGH 8.7 CVE-2026-44886 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnera… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44635 Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metachara… Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-44521 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.3 CVE-2026-38808 SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-38930 OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is explo… Mitigation only Fix from $1,6002026-05-27 HIGH 8.5 CVE-2026-49046 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Bli… Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-9617 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside … Anonymizer No fix yet Fix from $1,9502026-05-27 CRITICAL 9.3 CVE-2026-42761 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42747 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-buil… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42755 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allow… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42740 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Inj… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42727 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer… Mitigation only Fix from $2,3002026-05-27