Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-41889 pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar… Pgx 5.9.2+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-37431 Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.… Mitigation only Fix from $2,3002026-05-08 MEDIUM 6.3 CVE-2026-44337 PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL-backed knowledge-store imple… Praisonai 4.6.34+ Fix from $1,6002026-05-08 HIGH 8.1 CVE-2026-41496 PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input v… Praisonaiagents 1.6.9 / 4.6.9+ Fix from $1,9502026-05-08 HIGH 8.6 CVE-2026-4935 The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, … Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2023-46453 Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both… Mitigation only Fix from $2,3002026-05-08 HIGH 7.3 CVE-2024-33288 Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page. No fix yet Fix from $1,9502026-05-08 MEDIUM 6.3 CVE-2024-33722 SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[]. Mitigation only Fix from $1,6002026-05-08 HIGH 7.3 CVE-2026-8133 A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file d… Patch available Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-8132 A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of… Mitigation only Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-8129 A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Execu… Mitigation only Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-8130 A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipu… Mitigation only Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-8131 A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The … Mitigation only Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-42208 KEVEPSS 89% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… Litellm 1.83.7+ Fix from $2,3002026-05-08 HIGH 7.3 CVE-2026-8126 A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulatio… Mitigation only Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-8128 A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Perf… Mitigation only Fix from $1,9502026-05-08 MEDIUM 6.3 CVE-2026-8125 A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipu… Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.3 CVE-2026-8114 A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of t… Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.3 CVE-2026-8097 A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipul… Mitigation only Fix from $1,6002026-05-07 HIGH 7.3 CVE-2026-8098 A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. S… Mitigation only Fix from $1,9502026-05-07 HIGH 7.3 CVE-2026-8083 A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_u… Mitigation only Fix from $1,9502026-05-07 HIGH 7.1 CVE-2026-44349 Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_findallpaginated.go:1484 splits th… Mitigation only Fix from $1,9502026-05-07 HIGH 8.3 CVE-2026-41422 Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that… Mitigation only Fix from $1,9502026-05-07 HIGH 8.3 CVE-2026-41490 Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior … Mitigation only Fix from $1,9502026-05-07 HIGH 7.6 CVE-2025-68060 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. … Mitigation only Fix from $1,9502026-05-07 HIGH 7.2 CVE-2026-41641 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQ… Nocobase 2.0.39+ Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-4348 The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in al… Mitigation only Fix from $1,9502026-05-07 HIGH 8.8 CVE-2026-41143 YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/… Mitigation only Fix from $1,9502026-05-07 HIGH 8.8 CVE-2026-41640 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryPa… Nocobase 2.0.39+ Fix from $1,9502026-05-07 HIGH 8.8 CVE-2026-29090 ### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.crea… Rucio 35.8.5 / 38.5.5+ Fix from $1,9502026-05-06