Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 5.8 CVE-2026-72775 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifi… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-72750 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates ex… No fix yet Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-72609 An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_re… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72607 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_ba… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-72608 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_cr… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-72562 An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-72599 An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. Th… No fix yet Fix from $5,7502026-08-11 HIGH 8.8 CVE-2026-72558 An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE cla… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-72550 An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statement… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.8 CVE-2026-19425 Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb… No fix yet Fix from $5,7502026-08-11 MEDIUM 6.3 CVE-2026-66770 Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72908 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.3 CVE-2025-13294 An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke… No fix yet Fix from $5,7502026-08-10 CRITICAL 10.0 CVE-2026-72898 KEVEPSS 10% Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access … Metabase 0.58.24 / 0.59.21+ Fix from $5,7502026-08-10 CRITICAL 10.0 CVE-2026-72899 Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p… No fix yet Fix from $5,7502026-08-10 HIGH 7.1 CVE-2026-72731 Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-63106 ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-72565 A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read ar… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-32227 SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.1 CVE-2026-19053 The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unau… No fix yet Fix from $5,7502026-08-10 HIGH 8.6 CVE-2026-19049 The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.8 CVE-2026-16949 The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthent… No fix yet Fix from $4,0002026-08-10 HIGH 7.3 CVE-2026-19384 A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admi… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.3 CVE-2026-19364 A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorcon… No fix yet Fix from $4,0002026-08-09 HIGH 7.3 CVE-2026-19355 A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/lis… No fix yet Fix from $4,9002026-08-09 MEDIUM 6.3 CVE-2026-19354 A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file c… No fix yet Fix from $4,0002026-08-09 HIGH 7.3 CVE-2026-19351 A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/Sel… No fix yet Fix from $4,9002026-08-09 MEDIUM 6.3 CVE-2026-19347 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php… No fix yet Fix from $4,0002026-08-09 HIGH 7.3 CVE-2026-19344 A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/co… No fix yet Fix from $4,9002026-08-09 HIGH 7.3 CVE-2026-19343 A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Admi… No fix yet Fix from $4,9002026-08-09