Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.1 CVE-2018-25346 WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database querie… No fix yet Fix from $1,9502026-05-23 HIGH 7.1 CVE-2018-25347 WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries … No fix yet Fix from $1,9502026-05-23 HIGH 8.2 CVE-2018-25348 Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inje… No fix yet Fix from $1,9502026-05-23 HIGH 8.2 CVE-2018-25340 Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code… No fix yet Fix from $1,9502026-05-23 HIGH 8.2 CVE-2018-25341 Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code… No fix yet Fix from $1,9502026-05-23 MEDIUM 6.3 CVE-2026-9305 A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file… Mitigation only Fix from $1,6002026-05-23 HIGH 8.8 CVE-2026-41075 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injectio… Mitigation only Fix from $1,9502026-05-22 HIGH 8.7 CVE-2026-25606 A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for … Mitigation only Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-4834 The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This i… Mitigation only Fix from $1,9502026-05-22 HIGH 7.1 CVE-2026-48233 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET parameter is concatenated into … Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48234 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort and dir GET parameters are con… Patch available Fix from $1,9502026-05-21 HIGH 8.2 CVE-2026-48235 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude, an… Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48236 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, t… Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48237 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are con… Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48238 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET parameter is concatenated into the WH… Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48239 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into the … Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48240 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are con… Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48231 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters (tablename, indexname, sortby… Patch available Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-48232 Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GET parameter is concatenated i… Patch available Fix from $1,9502026-05-21 CRITICAL 9.3 CVE-2026-39531 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind … Mitigation only Fix from $2,3002026-05-21 HIGH 8.8 CVE-2026-44047 An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorize… Mitigation only Fix from $1,9502026-05-21 CRITICAL 9.8 CVE-2026-9082 KEVEPSS 88% Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This … Drupal 10.4.10 / 10.5.10+ Fix from $2,3002026-05-20 MEDIUM 6.5 CVE-2026-44923 SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. Infoscale Operations Manager 9.1.3+ Fix from $1,6002026-05-20 HIGH 7.6 CVE-2026-42383 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Bl… Mitigation only Fix from $1,9502026-05-20 CRITICAL 9.3 CVE-2026-9059 NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.3 CVE-2026-9065 SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'p… Mitigation only Fix from $2,3002026-05-20 HIGH 7.5 CVE-2026-9003 E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQ… Mitigation only Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-9010 The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and incl… Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-8685 The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including… Mitigation only Fix from $1,6002026-05-20 HIGH 7.5 CVE-2026-3985 The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parame… Mitigation only Fix from $1,9502026-05-20