Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.1 CVE-2026-18473 The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a… No fix yet Fix from $5,7502026-08-09 HIGH 8.6 CVE-2026-17044 The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading t… No fix yet Fix from $4,9002026-08-09 HIGH 8.1 CVE-2026-17017 The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an A… No fix yet Fix from $4,9002026-08-09 HIGH 7.7 CVE-2026-16589 The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its aut… No fix yet Fix from $1,9502026-08-08 HIGH 7.3 CVE-2026-19231 A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /adm… No fix yet Fix from $1,9502026-08-07 HIGH 7.7 CVE-2026-64636 An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the pan… No fix yet Fix from $1,9502026-08-07 HIGH 7.3 CVE-2026-19211 A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Per… No fix yet Fix from $1,9502026-08-07 HIGH 8.2 CVE-2026-66838 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via t… Postgrex No fix yet Fix from $1,9502026-08-07 HIGH 7.3 CVE-2026-19196 A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=… No fix yet Fix from $1,9502026-08-07 HIGH 8.1 CVE-2026-15361 The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2026-67689 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated … No fix yet Fix from $2,3002026-08-06 MEDIUM 6.3 CVE-2026-19067 A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatmen… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19068 A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /treatmentdeta… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19069 A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /treatmentrec… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19070 A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipul… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19071 A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipula… No fix yet Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-19062 A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/se… No fix yet Fix from $1,9502026-08-06 HIGH 8.6 CVE-2026-3430 The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unaut… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.3 CVE-2026-66447 Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. No fix yet Fix from $2,3002026-08-06 HIGH 8.5 CVE-2026-65569 Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. No fix yet Fix from $1,9502026-08-06 CRITICAL 9.3 CVE-2026-65546 Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. No fix yet Fix from $2,3002026-08-06 HIGH 8.5 CVE-2026-65547 Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. No fix yet Fix from $1,9502026-08-06 CRITICAL 9.3 CVE-2026-65520 Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.3 CVE-2026-65508 Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-34191 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora… Apr Util after 1.6.3 Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-5134 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.3 CVE-2026-19020 A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-19021 A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown funct… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-16065 The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL st… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.1 CVE-2026-12713 The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin… No fix yet Fix from $2,3002026-08-06