Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.6 CVE-2026-42646 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind … Mitigation only Fix from $1,9502026-04-29 CRITICAL 10.0 CVE-2026-3325 SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The v… Mitigation only Fix from $2,3002026-04-29 HIGH 8.1 CVE-2026-42167 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER reques… Proftpd after 1.3.9b Fix from $1,9502026-04-28 MEDIUM 6.3 CVE-2026-7290 A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boot/jeecg-boot-base-core/src/ma… Patch available Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7266 A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.… Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7267 A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation … Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7268 A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?ac… Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7265 A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file … Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.3 CVE-2026-7264 A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?ac… Mitigation only Fix from $1,6002026-04-28 HIGH 8.8 CVE-2026-40978 SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affecte… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,9502026-04-28 MEDIUM 6.3 CVE-2026-7229 A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php… Mitigation only Fix from $1,6002026-04-28 HIGH 7.3 CVE-2026-7225 A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7226 A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7227 A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login.… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7228 A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7224 A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7206 A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. … Patch available Fix from $1,9502026-04-28 MEDIUM 6.3 CVE-2026-7196 A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipul… Mitigation only Fix from $1,6002026-04-28 HIGH 7.3 CVE-2026-7199 A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7194 A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?acti… Mitigation only Fix from $1,9502026-04-27 CRITICAL 9.4 CVE-2024-46636 NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category … Mitigation only Fix from $2,3002026-04-27 HIGH 7.0 CVE-2026-5394 An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and … Patch available Fix from $1,9502026-04-27 MEDIUM 6.3 CVE-2026-7148 A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the arg… Mitigation only Fix from $1,6002026-04-27 MEDIUM 6.5 CVE-2021-36438 SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php. Mitigation only Fix from $1,6002026-04-27 MEDIUM 6.3 CVE-2026-7143 A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_… Mitigation only Fix from $1,6002026-04-27 CRITICAL 9.8 CVE-2026-41462 ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is d… Mitigation only Fix from $2,3002026-04-27 HIGH 7.3 CVE-2026-7131 A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /log… Mitigation only Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7130 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?ac… Mitigation only Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7126 A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?act… Mitigation only Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7127 A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /ajax.p… Mitigation only Fix from $1,9502026-04-27