Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.5 CVE-2026-28168 Subscriber SQL Injection in CubeWP <= 1.1.30 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.5 CVE-2026-28156 Subscriber SQL Injection in Do Lasso <= 358 versions. No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-28001 Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. No fix yet Fix from $5,7502026-08-13 HIGH 8.5 CVE-2026-28002 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. … No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-28142 Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. No fix yet Fix from $5,7502026-08-13 HIGH 7.5 CVE-2026-27538 Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-15741 SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attack… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-11840 Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL inj… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-73331 CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges … No fix yet Fix from $4,9002026-08-12 HIGH 8.7 CVE-2026-73332 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers t… No fix yet Fix from $4,9002026-08-12 HIGH 8.0 CVE-2026-72807 SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks funct… No fix yet Fix from $4,9002026-08-12 HIGH 7.4 CVE-2026-67579 Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged … Ash Framework No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-17111 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta… I No fix yet Fix from $5,7502026-08-12 CRITICAL 9.6 CVE-2026-73300 Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru… No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-44741 Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's … No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-17418 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elemen… I after 7.6 Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-17419 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used… I after 7.6 Fix from $4,0002026-08-12 CRITICAL 9.3 CVE-2026-66659 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject… No fix yet Fix from $5,7502026-08-12 HIGH 8.6 CVE-2026-18474 The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL inje… No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-18230 The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its aut… No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-18057 The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing u… No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-16977 The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQ… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-13613 The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-73211 PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.0 CVE-2026-48381 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2016-20097 Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to … No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2022-50997 Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated rem… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65673 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to… Entra Connect No fix yet Fix from $4,9002026-08-11 CRITICAL 9.1 CVE-2026-73069 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MOD… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.8 CVE-2026-46670 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat… No fix yet Fix from $5,7502026-08-11