Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-34934 PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with u… Praisonai 4.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.0 CVE-2026-34612 Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Inje… Kestra 1.3.7+ Fix from $2,3002026-04-03 HIGH 7.2 CVE-2026-27834 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getLis… Piwigo 16.3.0+ Fix from $1,9502026-04-03 HIGH 7.2 CVE-2026-27885 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affec… Piwigo 16.3.0+ Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-27634 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max… Piwigo 16.3.0+ Fix from $2,3002026-04-03 MEDIUM 6.5 CVE-2026-25773 ** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reor… Focalboard Mitigation only Fix from $1,6002026-04-03 MEDIUM 6.5 CVE-2026-34825 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase pl… Nocobase 2.0.30+ Fix from $1,6002026-04-02 CRITICAL 9.8 CVE-2026-5368 A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the com… Car Rental Project Mitigation only Fix from $2,3002026-04-02 HIGH 8.1 CVE-2026-34717 OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat… Openproject 17.2.3+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-5334 A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=e… Online Enrollment System Mitigation only Fix from $2,3002026-04-02 HIGH 8.8 CVE-2026-35168 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) mod… Openstamanager 2.10.2+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-28805 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers i… Openstamanager 2.10.2+ Fix from $1,9502026-04-02 MEDIUM 6.3 CVE-2026-5328 A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listIt… Patch available Fix from $1,6002026-04-02 HIGH 7.5 CVE-2026-33616 An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutraliz… Mbconnect24 after 2.19.4 Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-33614 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization … Mbconnect24 after 2.19.4 Fix from $1,9502026-04-02 CRITICAL 9.1 CVE-2026-33615 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization … Mbconnect24 after 2.19.4 Fix from $2,3002026-04-02 HIGH 7.3 CVE-2026-5322 A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d.… Mitigation only Fix from $1,9502026-04-02 HIGH 8.2 CVE-2026-34747 Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An… Payload 3.79.1+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-34455 Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository… Hi.events 1.7.1+ Fix from $1,9502026-04-01 HIGH 7.3 CVE-2026-30273 pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component. Pandasai after 3.0.0 Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-21630 Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. Joomla\! 5.4.4 / 6.0.4+ Fix from $1,9502026-04-01 CRITICAL 9.8 CVE-2026-5256 A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Pa… Simple Laundry System Mitigation only Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-5257 A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php o… Simple Laundry System Mitigation only Fix from $2,3002026-04-01 HIGH 8.8 CVE-2025-13855 IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s… Storage Protect Server Mitigation only Fix from $1,9502026-04-01 HIGH 7.3 CVE-2026-5238 A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_… Mitigation only Fix from $1,9502026-04-01 MEDIUM 6.5 CVE-2026-4668 The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payment… Mitigation only Fix from $1,6002026-04-01 HIGH 7.3 CVE-2026-5237 A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the … Mitigation only Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-34400 Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, … Alerta 9.1.0+ Fix from $2,3002026-03-31 MEDIUM 6.3 CVE-2026-5206 A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the componen… Mitigation only Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-30520 A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specific… Loan Management System No fix yet Fix from $1,6002026-03-31