Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-11024 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. … Mitigation only Fix from $2,3002026-05-14 MEDIUM 6.5 CVE-2026-6225 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection vi… Mitigation only Fix from $1,6002026-05-14 HIGH 7.1 CVE-2026-46445 SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. Patch available Fix from $1,9502026-05-14 HIGH 7.1 CVE-2026-46446 SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@… Patch available Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-5486 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addon… Mitigation only Fix from $1,6002026-05-14 HIGH 8.1 CVE-2026-29206 Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging … Mitigation only Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-44446 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection t… Erpnext 15.104.3 / 16.14.0+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-44447 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through special… Erpnext 16.9.0+ Fix from $1,9502026-05-13 MEDIUM 5.3 CVE-2026-44381 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-contr… Misp 2.5.37+ Fix from $1,6002026-05-13 HIGH 8.7 CVE-2026-44418 EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view pass… Patch available Fix from $1,9502026-05-13 HIGH 7.2 CVE-2026-39358 CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorti… Mitigation only Fix from $1,9502026-05-13 HIGH 8.8 CVE-2026-42550 Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() build SQL stateme… Mitigation only Fix from $1,9502026-05-13 CRITICAL 9.8 CVE-2026-42031 CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor… Ckan 2.10.10 / 2.11.5+ Fix from $2,3002026-05-13 MEDIUM 6.1 CVE-2026-0242 A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product d… Mitigation only Fix from $1,6002026-05-13 HIGH 7.1 CVE-2020-37226 Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by inje… No fix yet Fix from $1,9502026-05-13 HIGH 8.2 CVE-2020-37218 Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQ… No fix yet Fix from $1,9502026-05-13 HIGH 7.1 CVE-2020-37224 Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by inje… No fix yet Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-4608 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all vers… Mitigation only Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-37429 qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vuln… Mitigation only Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-37428 qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vuln… Mitigation only Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-4798 The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and includi… Mitigation only Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-6929 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sort… Mitigation only Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-7619 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Inject… Mitigation only Fix from $1,6002026-05-13 HIGH 7.2 CVE-2026-6888 Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific i… Mitigation only Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-1250 The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all v… Mitigation only Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-44864 SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-44860 SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-44861 SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-44862 SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-44863 SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and manag… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12