Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.3 CVE-2026-30534 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter. Online Food Ordering System No fix yet Fix from $1,9502026-03-27 HIGH 8.8 CVE-2026-30529 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). … Online Food Ordering System No fix yet Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-30530 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer actio… Online Food Ordering System Mitigation only Fix from $2,3002026-03-27 HIGH 8.8 CVE-2026-30531 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category actio… Online Food Ordering System No fix yet Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-30532 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. Online Food Ordering System Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-30533 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. Online Food Ordering System Mitigation only Fix from $2,3002026-03-27 HIGH 7.3 CVE-2026-4955 A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. T… Mitigation only Fix from $1,9502026-03-27 HIGH 7.3 CVE-2026-4956 A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePr… Mitigation only Fix from $1,9502026-03-27 MEDIUM 6.3 CVE-2026-4954 A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/Conten… Mitigation only Fix from $1,6002026-03-27 HIGH 8.8 CVE-2026-33755 Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated … Group Office 6.8.158 / 25.0.92+ Fix from $1,9502026-03-27 CRITICAL 9.1 CVE-2026-27876 A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a… Grafana 11.6.0 / 12.0.0+ Fix from $2,3002026-03-27 HIGH 8.2 CVE-2026-24031 Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for… Dovecot 2.4.3 / 3.1.4+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-22743 Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is… Spring Ai 1.0.5 / 1.1.4+ Fix from $1,9502026-03-27 HIGH 7.3 CVE-2026-4910 A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /… Mitigation only Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-4908 A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the… Simple Laundry System Mitigation only Fix from $2,3002026-03-27 MEDIUM 6.5 CVE-2026-33545 MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 5… Mobile Security Framework 4.4.6+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33531 InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows … Inventree 1.2.6+ Fix from $1,6002026-03-26 HIGH 7.2 CVE-2026-33505 Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is v… Keto 26.2.0+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33153 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpo… Recipes 2.6.0+ Fix from $1,6002026-03-26 HIGH 7.7 CVE-2026-30463 Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component. Fuel Cms No fix yet Fix from $1,9502026-03-26 HIGH 7.2 CVE-2026-33504 Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrus… Hydra 26.2.0+ Fix from $1,9502026-03-26 HIGH 7.2 CVE-2026-33503 Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API i… Kratos 26.2.0+ Fix from $1,9502026-03-26 HIGH 8.1 CVE-2026-33468 Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes si… Kysely 0.28.14+ Fix from $1,9502026-03-26 HIGH 8.1 CVE-2026-33442 Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method in Kysely's query compiler es… Kysely 0.28.14+ Fix from $1,9502026-03-26 MEDIUM 6.3 CVE-2026-4876 A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_… Mitigation only Fix from $1,6002026-03-26 HIGH 7.5 CVE-2026-2511 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `… Mitigation only Fix from $1,9502026-03-26 HIGH 7.5 CVE-2025-55262 HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab… Aftermarket Cloud Mitigation only Fix from $1,9502026-03-26 HIGH 8.2 CVE-2018-25208 qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through … Qdpm after 9.1 Fix from $1,9502026-03-26 HIGH 8.2 CVE-2018-25209 OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries… No fix yet Fix from $1,9502026-03-26 HIGH 8.2 CVE-2018-25203 Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting… No fix yet Fix from $1,9502026-03-26