Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.3 CVE-2026-6005 A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_prin… Mitigation only Fix from $1,6002026-04-10 HIGH 7.3 CVE-2026-6004 A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Perfo… Mitigation only Fix from $1,9502026-04-10 HIGH 7.3 CVE-2026-5985 A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.ph… Mitigation only Fix from $1,9502026-04-09 HIGH 8.2 CVE-2023-54359 WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate datab… No fix yet Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5961 A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects unknown code of the file /topi… Mitigation only Fix from $1,9502026-04-09 HIGH 7.2 CVE-2026-4112 Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic… Sma6210 Firmware 12.4.3-03387 / 12.5.0-02624+ Fix from $1,9502026-04-09 HIGH 8.8 CVE-2026-34185 AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker… Control System 9.8.5+ Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5837 A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the … Mitigation only Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5828 A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomm… Mitigation only Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5829 A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/conten… Mitigation only Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5827 A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. T… Mitigation only Fix from $1,9502026-04-09 MEDIUM 6.3 CVE-2026-5823 A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /… Mitigation only Fix from $1,6002026-04-09 HIGH 7.3 CVE-2026-5824 A security vulnerability has been detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /userchecklogin.php. … Mitigation only Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5814 A security vulnerability has been detected in PHPGurukul Online Course Registration 3.1. This issue affects some unknown processing of the file /admi… Mitigation only Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-5813 A weakness has been identified in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /check_availability.… Mitigation only Fix from $1,9502026-04-08 HIGH 7.3 CVE-2026-5805 A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.p… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-33350 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris 27.0.3+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-3396 WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and i… Mitigation only Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-1865 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buil… Mitigation only Fix from $1,6002026-04-08 HIGH 7.6 CVE-2026-39497 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher al… Mitigation only Fix from $1,9502026-04-08 HIGH 8.5 CVE-2026-39486 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allo… Mitigation only Fix from $1,9502026-04-08 HIGH 7.6 CVE-2026-39487 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind… Mitigation only Fix from $1,9502026-04-08 HIGH 8.5 CVE-2026-39495 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-sc… Mitigation only Fix from $1,9502026-04-08 HIGH 7.6 CVE-2026-39496 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL In… Mitigation only Fix from $1,9502026-04-08 HIGH 7.6 CVE-2026-39475 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite all… Mitigation only Fix from $1,9502026-04-08 HIGH 7.6 CVE-2026-39479 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Bl… Mitigation only Fix from $1,9502026-04-08 CRITICAL 9.8 CVE-2026-33088 Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. Movable Type 8.0.10 / 8.8.3+ Fix from $2,3002026-04-08 HIGH 7.6 CVE-2026-39466 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform B… Mitigation only Fix from $1,9502026-04-08 MEDIUM 5.4 CVE-2026-3781 The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all versions up to, and including, 0.6.2… Mitigation only Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-24913 SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be… Matcha Invoice after 2.6.6 Fix from $1,9502026-04-08