Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2026-39356 Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific … Drizzle 0.45.2+ Fix from $1,9502026-04-07 HIGH 7.3 CVE-2026-5736 A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src… Patch available Fix from $1,9502026-04-07 HIGH 8.1 CVE-2026-39340 ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the adm… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.1 CVE-2026-39341 ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper in… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39342 ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 7.2 CVE-2026-39343 ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is o… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39334 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.ph… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39329 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. … Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39330 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 7.2 CVE-2026-39325 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in C… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39326 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.ph… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39327 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php … Churchcrm 7.1.0+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39318 ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRo… Churchcrm after 7.0.5 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-39319 ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaise… Churchcrm 7.1.0+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-35614 Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix… Frappe 15.104.0 / 16.14.0+ Fix from $2,3002026-04-07 CRITICAL 9.9 CVE-2026-23696EPSS 16% Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allo… Patch available Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2024-36058 The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parame… Mitigation only Fix from $2,3002026-04-07 MEDIUM 6.4 CVE-2026-5372 An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Imp… Runzero Platform Mitigation only Fix from $1,6002026-04-07 MEDIUM 6.5 CVE-2026-4079 The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for at… Sql Chart Builder 2.3.8+ Fix from $1,6002026-04-07 MEDIUM 6.3 CVE-2026-5719 A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a… Mitigation only Fix from $1,6002026-04-07 HIGH 8.8 CVE-2026-35395 WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection … Wegia 3.6.9+ Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5681 A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the com… Mitigation only Fix from $1,6002026-04-06 CRITICAL 9.8 CVE-2026-35184 EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the… Ecclesiacrm 8.0.0+ Fix from $2,3002026-04-06 HIGH 7.3 CVE-2026-5672 A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edi… Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5675 A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the comp… Mitigation only Fix from $1,6002026-04-06 HIGH 8.8 CVE-2026-35470 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across differ… Openstamanager 2.10.2+ Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5669 A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unkn… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5665 A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the … Mitigation only Fix from $1,9502026-04-06 HIGH 8.5 CVE-2026-34885 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQ… Mitigation only Fix from $1,9502026-04-06 CRITICAL 9.8 CVE-2026-26263EPSS 9% GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL… Glpi 11.0.6+ Fix from $2,3002026-04-06