Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.3 CVE-2026-9525 A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The man… Mitigation only Fix from $1,9502026-05-26 CRITICAL 9.3 CVE-2026-42774 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. Thi… Mitigation only Fix from $2,3002026-05-25 HIGH 8.5 CVE-2026-48837 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind S… Mitigation only Fix from $1,9502026-05-25 CRITICAL 9.3 CVE-2026-42773 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind … Mitigation only Fix from $2,3002026-05-25 HIGH 8.1 CVE-2026-48842 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() b… Patch available Fix from $1,9502026-05-25 HIGH 7.3 CVE-2026-9474 A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the f… Mitigation only Fix from $1,9502026-05-25 MEDIUM 6.6 CVE-2026-27768 SQL Injection affecting the Access Manager role. No fix yet Fix from $1,6002026-05-25 HIGH 7.3 CVE-2026-9469 A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unkno… Mitigation only Fix from $1,9502026-05-25 HIGH 7.3 CVE-2026-9470 A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the fun… Mitigation only Fix from $1,9502026-05-25 HIGH 7.3 CVE-2026-9465 A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebS… Mitigation only Fix from $1,9502026-05-25 HIGH 8.2 CVE-2018-25379 Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipula… No fix yet Fix from $1,9502026-05-25 HIGH 7.1 CVE-2018-25380 Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands throu… No fix yet Fix from $1,9502026-05-25 HIGH 7.1 CVE-2018-25381 Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands throu… No fix yet Fix from $1,9502026-05-25 HIGH 8.2 CVE-2018-25372 MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries b… No fix yet Fix from $1,9502026-05-25 HIGH 8.2 CVE-2018-25364 Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious … No fix yet Fix from $1,9502026-05-25 HIGH 8.2 CVE-2018-25371 mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through … No fix yet Fix from $1,9502026-05-25 HIGH 8.2 CVE-2018-25362 Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code throu… No fix yet Fix from $1,9502026-05-25 MEDIUM 6.3 CVE-2026-9451 A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the fil… Mitigation only Fix from $1,6002026-05-25 HIGH 7.3 CVE-2026-9447 A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search… Mitigation only Fix from $1,9502026-05-25 MEDIUM 6.3 CVE-2026-9449 A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The … Mitigation only Fix from $1,6002026-05-25 MEDIUM 6.3 CVE-2026-9450 A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The ma… Mitigation only Fix from $1,6002026-05-25 MEDIUM 6.3 CVE-2026-9411 A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoi… Mitigation only Fix from $1,6002026-05-25 HIGH 7.3 CVE-2026-9383 A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The … Mitigation only Fix from $1,9502026-05-24 HIGH 7.3 CVE-2026-9364 A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a man… Mitigation only Fix from $1,9502026-05-24 HIGH 7.3 CVE-2026-9356 A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin… Mitigation only Fix from $1,9502026-05-24 HIGH 7.3 CVE-2026-9355 A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /cla… Mitigation only Fix from $1,9502026-05-24 MEDIUM 6.3 CVE-2026-9342 A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /a… Mitigation only Fix from $1,6002026-05-23 HIGH 8.2 CVE-2018-25351 Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu… No fix yet Fix from $1,9502026-05-23 HIGH 7.1 CVE-2018-25352 WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to ma… No fix yet Fix from $1,9502026-05-23 HIGH 8.2 CVE-2018-25342 Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting… No fix yet Fix from $1,9502026-05-23