Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2026-40816 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm funct… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40817 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutra… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40818 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper ne… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40819 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization … Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40810 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40811 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralizatio… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40812 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions sn parameter due to impr… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40813 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to i… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40814 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _mb24confi_getTagAlarm functio… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-40815 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper… Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-9606 A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such mani… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.3 CVE-2026-9607 A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Pe… Mitigation only Fix from $1,6002026-05-27 HIGH 7.3 CVE-2026-9584 A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the… Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9573 A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/studen… Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9574 A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/st… Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9575 A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admi… Mitigation only Fix from $1,9502026-05-26 CRITICAL 9.9 CVE-2026-46624 Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL … Twenty 1.16.7+ Fix from $2,3002026-05-26 HIGH 8.5 CVE-2026-44706 Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter API… Mitigation only Fix from $1,9502026-05-26 HIGH 7.6 CVE-2026-44680 MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-orm/knex 6.6.14 and @mikro-orm… Patch available Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-35221 Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-35222 Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2025-36220 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote atta… Cloud Pak For Data System Cyclops 11.3.0.2+ Fix from $2,3002026-05-26 HIGH 7.3 CVE-2026-9552 A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component S… Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9551 A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord… Mitigation only Fix from $1,9502026-05-26 HIGH 7.2 CVE-2026-42425 OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements… No fix yet Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-9542 A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php… Mitigation only Fix from $1,6002026-05-26 HIGH 7.3 CVE-2026-9544 A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown… Mitigation only Fix from $1,9502026-05-26 MEDIUM 5.6 CVE-2026-48134 When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who … Mitigation only Fix from $1,6002026-05-26 HIGH 7.3 CVE-2026-9526 A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. Th… Mitigation only Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9528 A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Su… Mitigation only Fix from $1,9502026-05-26