Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.5 CVE-2026-44204 Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /ass… Patch available Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-25088 An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, Forti… Fortindr 7.4.10 / 7.6.3+ Fix from $1,9502026-05-12 HIGH 7.2 CVE-2025-53681 An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7… Fortimail 7.2.9 / 7.4.6+ Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-34187 Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affec… Pandora Fms 777.17 / 802+ Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-8111 SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exe… Endpoint Manager after 2022 Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-43937 YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttri… Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-32687 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifica… Postgrex 0.22.0+ Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2026-27851 When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe… Dovecot 2.4.4 / 3.1.5+ Fix from $2,3002026-05-12 HIGH 7.7 CVE-2026-45218 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL … Mitigation only Fix from $1,9502026-05-12 HIGH 8.5 CVE-2026-42741 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Ed… Mitigation only Fix from $1,9502026-05-12 HIGH 8.5 CVE-2026-42742 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite a… Mitigation only Fix from $1,9502026-05-12 HIGH 8.5 CVE-2026-45211 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce wo… Mitigation only Fix from $1,9502026-05-12 HIGH 7.6 CVE-2026-45213 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQ… Mitigation only Fix from $1,9502026-05-12 HIGH 8.5 CVE-2026-45214 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addon… Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.0 CVE-2026-41125 A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions… Mitigation only Fix from $1,6002026-05-12 CRITICAL 9.8 CVE-2025-6577 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. … Mitigation only Fix from $2,3002026-05-12 MEDIUM 6.5 CVE-2026-5028 The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-artic… No fix yet Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-2993 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insu… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.6 CVE-2026-34260 SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL sta… Mitigation only Fix from $2,3002026-05-12 HIGH 7.3 CVE-2026-36962 SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative … Mitigation only Fix from $1,9502026-05-11 CRITICAL 9.8 CVE-2026-38567 HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries witho… Mitigation only Fix from $2,3002026-05-11 HIGH 8.8 CVE-2026-7815 SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup… Pgadmin 4 9.15+ Fix from $1,9502026-05-11 MEDIUM 6.0 CVE-2026-6093 Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issu… Mitigation only Fix from $1,6002026-05-11 HIGH 8.2 CVE-2021-47941 WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries… No fix yet Fix from $1,9502026-05-10 HIGH 8.2 CVE-2021-47930 Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attacker… No fix yet Fix from $1,9502026-05-10 HIGH 8.2 CVE-2021-47928 Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by … No fix yet Fix from $1,9502026-05-10 MEDIUM 6.3 CVE-2026-8231 A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The m… Mitigation only Fix from $1,6002026-05-10 CRITICAL 9.8 CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 HIGH 7.0 CVE-2026-8207 Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/Gib… Mitigation only Fix from $1,9502026-05-09 CRITICAL 10.0 CVE-2026-42287 Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attack… Mitigation only Fix from $2,3002026-05-08