Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2026-29080 A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend … Rucio 35.8.5 / 38.5.5+ Fix from $1,9502026-05-06 HIGH 7.5 CVE-2026-1719 The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient esca… Mitigation only Fix from $1,9502026-05-06 CRITICAL 9.3 CVE-2026-40331 Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7… Mitigation only Fix from $2,3002026-05-05 HIGH 8.1 CVE-2026-44331 In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attac… Patch available Fix from $1,9502026-05-05 CRITICAL 9.3 CVE-2026-40329 Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc compone… Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.3 CVE-2026-40330 Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7… Mitigation only Fix from $2,3002026-05-05 HIGH 8.8 CVE-2026-33324 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vul… Sqlbot 1.7.1+ Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2026-38428 Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly conc… Kestra 1.0.35 / 1.3.7+ Fix from $2,3002026-05-05 HIGH 7.5 CVE-2026-4304 The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3.4.11 … Mitigation only Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-3359 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' param… Mitigation only Fix from $1,9502026-05-05 CRITICAL 9.3 CVE-2026-40797 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQ… Mitigation only Fix from $2,3002026-05-05 MEDIUM 6.3 CVE-2026-7822 A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The mani… Mitigation only Fix from $1,6002026-05-05 HIGH 7.5 CVE-2026-3456 The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attribute… Mitigation only Fix from $1,9502026-05-05 HIGH 8.7 CVE-2026-35228 Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is af… Mitigation only Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-5100 The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.… Mitigation only Fix from $1,9502026-05-05 MEDIUM 6.3 CVE-2026-7783 A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::applySortQuery of the file applic… Mitigation only Fix from $1,6002026-05-05 HIGH 8.8 CVE-2026-42237 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the… N8n 1.123.32 / 2.17.4+ Fix from $1,9502026-05-04 HIGH 8.8 CVE-2026-42229 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:… N8n 1.123.32 / 2.17.4+ Fix from $1,9502026-05-04 CRITICAL 9.8 CVE-2026-42233 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select opera… N8n 1.123.32 / 2.17.4+ Fix from $2,3002026-05-04 CRITICAL 9.6 CVE-2026-42087 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before … Cosmos 7.0.0+ Fix from $2,3002026-05-04 MEDIUM 6.3 CVE-2026-7745 A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This … Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7746 A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /produ… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7744 A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipul… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7741 A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7742 A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Execu… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7743 A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdet… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7731 A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file ge… Mitigation only Fix from $1,6002026-05-04 HIGH 7.3 CVE-2026-7727 A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineG… Mitigation only Fix from $1,9502026-05-04 MEDIUM 6.3 CVE-2026-7716 A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /inde… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7699 A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file Str… Mitigation only Fix from $1,6002026-05-03