Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.3 CVE-2026-7695 A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown func… Mitigation only Fix from $1,9502026-05-03 HIGH 7.3 CVE-2026-7694 A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown fu… Mitigation only Fix from $1,9502026-05-03 MEDIUM 5.0 CVE-2026-7688 A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedi… Mitigation only Fix from $1,6002026-05-03 MEDIUM 6.3 CVE-2026-7678 A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/ma… Mitigation only Fix from $1,6002026-05-03 MEDIUM 6.3 CVE-2026-7672 A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/co… Mitigation only Fix from $1,6002026-05-03 HIGH 7.3 CVE-2026-7670 A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manip… Mitigation only Fix from $1,9502026-05-02 HIGH 7.3 CVE-2026-7632 A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.… Mitigation only Fix from $1,9502026-05-02 HIGH 7.5 CVE-2026-4061 The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including,… Mitigation only Fix from $1,9502026-05-02 HIGH 7.5 CVE-2026-4062 The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all version… Mitigation only Fix from $1,9502026-05-02 HIGH 7.5 CVE-2026-4060 The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18.… Mitigation only Fix from $1,9502026-05-02 HIGH 8.8 CVE-2026-7489 CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,… Ehrd Ctms Mitigation only Fix from $1,9502026-05-02 HIGH 7.5 CVE-2026-7649 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based bli… Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.5 CVE-2026-6457 The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to,… Mitigation only Fix from $1,6002026-05-02 HIGH 7.3 CVE-2026-7592 A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the file /edit_staff.php. Executing… Mitigation only Fix from $1,9502026-05-01 MEDIUM 6.3 CVE-2026-7591 A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts … Mitigation only Fix from $1,6002026-05-01 MEDIUM 6.5 CVE-2026-42474 SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHelper.php. Mitigation only Fix from $1,6002026-05-01 MEDIUM 6.5 CVE-2026-42475 SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php. Mix Php after 2.2.17 Fix from $1,6002026-05-01 HIGH 7.3 CVE-2026-7555 A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/login.php. Such manip… Mitigation only Fix from $1,9502026-05-01 HIGH 7.3 CVE-2026-7549 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete… Mitigation only Fix from $1,9502026-05-01 HIGH 7.3 CVE-2026-7550 A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?actio… Mitigation only Fix from $1,9502026-05-01 HIGH 7.3 CVE-2026-7545 A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commo… Mitigation only Fix from $1,9502026-05-01 HIGH 7.3 CVE-2026-7506 A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/che… Mitigation only Fix from $1,9502026-04-30 HIGH 7.2 CVE-2026-7435 SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database executio… Mitigation only Fix from $1,9502026-04-30 MEDIUM 6.4 CVE-2026-3346 IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to emb… Langflow Desktop after 1.8.4 Fix from $1,6002026-04-30 MEDIUM 6.3 CVE-2026-7447 A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_custo… Mitigation only Fix from $1,6002026-04-30 MEDIUM 6.3 CVE-2026-7410 A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?ac… No fix yet Fix from $1,6002026-04-29 HIGH 8.2 CVE-2018-25300 XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inject… No fix yet Fix from $1,9502026-04-29 MEDIUM 6.3 CVE-2026-7391 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action… Mitigation only Fix from $1,6002026-04-29 MEDIUM 6.3 CVE-2026-7392 A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax… Mitigation only Fix from $1,6002026-04-29 HIGH 7.3 CVE-2026-7389 A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.ph… Mitigation only Fix from $1,9502026-04-29