Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2026-31069 BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter na… Mitigation only Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-8912 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This… Mitigation only Fix from $1,9502026-05-19 HIGH 8.2 CVE-2026-8726 The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrar… Mitigation only Fix from $1,9502026-05-19 HIGH 8.2 CVE-2026-8827 The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method … Mitigation only Fix from $1,9502026-05-19 HIGH 8.1 CVE-2026-8851 SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated u… Mitigation only Fix from $1,9502026-05-18 HIGH 8.6 CVE-2026-6379 The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing… Mitigation only Fix from $1,9502026-05-18 HIGH 7.3 CVE-2026-8785 A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of t… Mitigation only Fix from $1,9502026-05-18 HIGH 7.3 CVE-2026-8771 A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/… Mitigation only Fix from $1,9502026-05-18 HIGH 8.2 CVE-2018-25338 Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information usin… No fix yet Fix from $1,9502026-05-17 HIGH 8.2 CVE-2018-25339 Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time… No fix yet Fix from $1,9502026-05-17 HIGH 8.2 CVE-2018-25330 Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious c… No fix yet Fix from $1,9502026-05-17 HIGH 8.2 CVE-2018-25333 Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ… No fix yet Fix from $1,9502026-05-17 HIGH 7.1 CVE-2018-25319 Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecti… No fix yet Fix from $1,9502026-05-17 HIGH 7.3 CVE-2026-8734 A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the compon… Mitigation only Fix from $1,9502026-05-17 HIGH 7.2 CVE-2026-8724 A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the c… Dataease No fix yet Fix from $1,9502026-05-17 HIGH 7.1 CVE-2021-47980 Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code… No fix yet Fix from $1,9502026-05-16 HIGH 8.2 CVE-2021-47954 LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro… No fix yet Fix from $1,9502026-05-16 HIGH 8.2 CVE-2021-47956 EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting S… No fix yet Fix from $1,9502026-05-16 HIGH 8.2 CVE-2020-37242 Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inje… No fix yet Fix from $1,9502026-05-16 HIGH 8.2 CVE-2020-37243 Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute ar… No fix yet Fix from $1,9502026-05-16 HIGH 8.2 CVE-2020-37244 Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injectin… No fix yet Fix from $1,9502026-05-16 HIGH 7.5 CVE-2026-46359 phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQ… Mitigation only Fix from $1,9502026-05-15 CRITICAL 9.8 CVE-2026-46364 phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha()… Patch available Fix from $2,3002026-05-15 HIGH 8.7 CVE-2026-45800 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an authenticated S… Mitigation only Fix from $1,9502026-05-15 HIGH 8.2 CVE-2021-47966 PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows u… No fix yet Fix from $1,9502026-05-15 HIGH 7.1 CVE-2026-42847 ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) vulnerability in ClipBucket, … Mitigation only Fix from $1,9502026-05-14 HIGH 7.2 CVE-2026-22599 Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a d… Strapi 4.26.1 / 5.33.2+ Fix from $1,9502026-05-14 HIGH 7.2 CVE-2026-6476 SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The a… PostgreSQL 17.10 / 18.4+ Fix from $1,9502026-05-14 HIGH 8.8 CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user runni… PostgreSQL 14.23 / 15.18+ Fix from $1,9502026-05-14 HIGH 8.8 CVE-2026-6638 SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL… PostgreSQL 16.14 / 17.10+ Fix from $1,9502026-05-14