Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2026-33084 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort pa… Dataease 2.10.21+ Fix from $1,9502026-04-16 HIGH 8.8 CVE-2026-33121 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API dat… Dataease 2.10.21+ Fix from $1,9502026-04-16 CRITICAL 9.8 CVE-2026-33082 DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export f… Dataease 2.10.21+ Fix from $2,3002026-04-16 HIGH 8.8 CVE-2026-33083 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDi… Dataease 2.10.21+ Fix from $1,9502026-04-16 HIGH 7.2 CVE-2026-37341 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php. No fix yet Fix from $1,9502026-04-16 HIGH 7.2 CVE-2026-37342 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php. Mitigation only Fix from $1,9502026-04-16 HIGH 7.2 CVE-2026-37343 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php. Mitigation only Fix from $1,9502026-04-16 HIGH 7.2 CVE-2026-37344 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php. Mitigation only Fix from $1,9502026-04-16 CRITICAL 9.8 CVE-2026-37345 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2026-37347 SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. Mitigation only Fix from $2,3002026-04-16 HIGH 7.3 CVE-2026-37336 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php. Mitigation only Fix from $1,9502026-04-16 HIGH 7.3 CVE-2026-37337 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php. Mitigation only Fix from $1,9502026-04-16 CRITICAL 9.4 CVE-2026-37338 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-37339 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-37340 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. Mitigation only Fix from $2,3002026-04-16 HIGH 8.1 CVE-2026-5785 Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated S… Mitigation only Fix from $1,9502026-04-16 HIGH 7.5 CVE-2026-3489 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in… Mitigation only Fix from $1,9502026-04-16 MEDIUM 6.5 CVE-2026-3773 The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter in all versions up to, and in… Mitigation only Fix from $1,6002026-04-16 HIGH 7.5 CVE-2026-3599 The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-js… Mitigation only Fix from $1,9502026-04-16 HIGH 8.6 CVE-2026-30995 Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint. Mitigation only Fix from $1,9502026-04-15 MEDIUM 6.5 CVE-2026-20061 A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injec… Unity Connection after 12.5 Fix from $1,6002026-04-15 HIGH 7.6 CVE-2025-63029 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marke… Mitigation only Fix from $1,9502026-04-15 HIGH 8.5 CVE-2026-40744 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-li… Mitigation only Fix from $1,9502026-04-15 HIGH 7.6 CVE-2026-40745 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes… Mitigation only Fix from $1,9502026-04-15 HIGH 7.2 CVE-2026-33714 Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint… Chamilo Lms Mitigation only Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32176 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6485.1 / 13.0.7080.1+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32167 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6485.1 / 13.0.7080.1+ Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-39815 A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may … Fortiddos F 7.2.3+ Fix from $1,9502026-04-14 MEDIUM 6.7 CVE-2026-39809 A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, … Forticlientems 7.2.13 / 7.4.6+ Fix from $1,6002026-04-14 HIGH 7.1 CVE-2026-38528 Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php. Mitigation only Fix from $1,9502026-04-14