Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.9 CVE-2026-41457 OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arb… Patch available Fix from $1,6002026-04-22 HIGH 8.8 CVE-2026-40906 Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based… Sync Service 1.5.0+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-41320 Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a … Frappe Hr 14.38.1 / 15.54.0+ Fix from $1,6002026-04-21 CRITICAL 9.1 CVE-2026-40887 Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL… Mitigation only Fix from $2,3002026-04-21 HIGH 7.2 CVE-2026-40871EPSS 10% mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerabili… Mitigation only Fix from $1,9502026-04-21 CRITICAL 9.3 CVE-2025-41029 SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete da… Mitigation only Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-6674 The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and i… Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.3 CVE-2026-35588 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassan… Glances 4.5.4+ Fix from $1,6002026-04-21 CRITICAL 9.4 CVE-2026-39109 SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the lo… Mitigation only Fix from $2,3002026-04-20 HIGH 8.2 CVE-2026-39110 SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgo… Mitigation only Fix from $1,9502026-04-20 HIGH 7.5 CVE-2026-39111 SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot pa… Mitigation only Fix from $1,9502026-04-20 MEDIUM 5.3 CVE-2025-66335 Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio… Doris Mcp Server 0.6.1+ Fix from $1,6002026-04-20 HIGH 7.3 CVE-2026-6629 A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file … Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6628 A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query… Mitigation only Fix from $1,6002026-04-20 CRITICAL 9.8 CVE-2026-5963 EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r… Easyflow .net after 6.6.17 Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-5964 EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r… Easyflow .net after 6.6.17 Fix from $2,3002026-04-20 HIGH 7.3 CVE-2026-6595 A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability aff… Mitigation only Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6562 A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a ma… Mitigation only Fix from $1,9502026-04-19 HIGH 7.1 CVE-2026-40482 ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via uns… Patch available Fix from $1,9502026-04-18 HIGH 8.8 CVE-2026-40285 WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. T… Mitigation only Fix from $1,9502026-04-17 CRITICAL 9.8 CVE-2026-37749 A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication … Mitigation only Fix from $2,3002026-04-17 HIGH 7.3 CVE-2026-6490 A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/del… Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.3 CVE-2026-6488 A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file a… Mitigation only Fix from $1,6002026-04-17 CRITICAL 9.8 CVE-2025-15625 Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. Pro Cloud Server Mitigation only Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-34018 An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. Cubecart 6.6.0+ Fix from $2,3002026-04-17 MEDIUM 6.5 CVE-2026-6080 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the … Mitigation only Fix from $1,6002026-04-17 MEDIUM 6.5 CVE-2026-4817 The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'o… Mitigation only Fix from $1,6002026-04-17 HIGH 8.8 CVE-2026-40900 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api… Dataease 2.10.21+ Fix from $1,9502026-04-16 CRITICAL 9.8 CVE-2026-33122 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API dat… Dataease 2.10.21+ Fix from $2,3002026-04-16 HIGH 8.8 CVE-2026-33207 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /dataso… Dataease 2.10.21+ Fix from $1,9502026-04-16