Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2026-29047 GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection … Glpi 10.0.24 / 11.0.6+ Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5660 A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_… Mitigation only Fix from $1,6002026-04-06 MEDIUM 6.3 CVE-2026-5649 A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /… Mitigation only Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5645 A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.ph… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5646 A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file logi… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5648 A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the … Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5641 A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-ima… Mitigation only Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5637 A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown code of the file /message_admin… Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5639 A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the c… Mitigation only Fix from $1,6002026-04-06 MEDIUM 6.3 CVE-2026-5640 A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/updat… Mitigation only Fix from $1,6002026-04-06 MEDIUM 6.3 CVE-2026-5636 A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the com… Mitigation only Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5634 A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /book_… Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5635 A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the fil… Mitigation only Fix from $1,6002026-04-06 MEDIUM 6.3 CVE-2026-5620 A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report… Mitigation only Fix from $1,6002026-04-06 MEDIUM 6.3 CVE-2026-5606 A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-… Mitigation only Fix from $1,6002026-04-06 MEDIUM 6.3 CVE-2026-5596 A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool… Mitigation only Fix from $1,6002026-04-05 CRITICAL 9.1 CVE-2019-25694 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25696 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the lan… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25698 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25700 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sor… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25702 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25704 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the fil… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25688 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code… Kados No fix yet Fix from $2,3002026-04-05 HIGH 8.2 CVE-2019-25690 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng… Kados No fix yet Fix from $1,9502026-04-05 CRITICAL 9.1 CVE-2019-25692 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2019-25680 Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by … Advance Gift Shop Pro Script after 2.0.3 Fix from $2,3002026-04-05 HIGH 8.2 CVE-2019-25684 OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t… Opendocman after 1.3.4 Fix from $1,9502026-04-05 CRITICAL 9.8 CVE-2019-25674 CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug… Cmssite Mitigation only Fix from $2,3002026-04-05 HIGH 7.5 CVE-2019-25675 eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose s… Edirectory after 1.0 Fix from $1,9502026-04-05 CRITICAL 9.8 CVE-2019-25676 Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code… Ask Expert Script Mitigation only Fix from $2,3002026-04-05