Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.3 CVE-2026-4540 A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of t… Mitigation only Fix from $1,9502026-03-22 HIGH 8.8 CVE-2026-4533 A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-t… Simple Food Order System No fix yet Fix from $1,9502026-03-22 MEDIUM 5.3 CVE-2026-4530 A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriev… Mitigation only Fix from $1,6002026-03-22 HIGH 7.5 CVE-2019-25581 i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou… I Doit No fix yet Fix from $1,9502026-03-21 HIGH 8.2 CVE-2019-25575 SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal… Simplepress Cms after 1.0.7 Fix from $1,9502026-03-21 HIGH 8.2 CVE-2019-25576 Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecti… Kepler Wallpaper Script No fix yet Fix from $1,9502026-03-21 HIGH 8.2 CVE-2019-25578 phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious co… Phptransformer No fix yet Fix from $1,9502026-03-21 HIGH 8.8 CVE-2019-25573 Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious cod… Greencms after 2.3.0603 Fix from $1,9502026-03-21 MEDIUM 6.3 CVE-2026-4513 A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py.… Mitigation only Fix from $1,6002026-03-21 MEDIUM 6.5 CVE-2026-4087 The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pprh_update_hints AJAX action i… Mitigation only Fix from $1,6002026-03-21 HIGH 8.8 CVE-2026-3334 The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in… Mitigation only Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-2503 The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_pos… Mitigation only Fix from $1,6002026-03-21 HIGH 7.5 CVE-2026-2468 The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to, and including, 1.2.12. This … Mitigation only Fix from $1,9502026-03-21 HIGH 7.2 CVE-2026-2279 The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and includin… Mitigation only Fix from $1,9502026-03-21 HIGH 7.5 CVE-2026-1800 The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions… Mitigation only Fix from $1,9502026-03-21 HIGH 7.3 CVE-2026-4508 A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberCo… Mitigation only Fix from $1,9502026-03-20 MEDIUM 6.3 CVE-2026-4507 A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the file mindsql/core/mindsql_cor… Mitigation only Fix from $1,6002026-03-20 HIGH 8.1 CVE-2026-33142 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection v… Oneuptime 10.0.34+ Fix from $1,9502026-03-20 HIGH 7.3 CVE-2026-4504 A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomp… Mitigation only Fix from $1,9502026-03-20 MEDIUM 6.7 CVE-2025-62846 An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulne… Qurouter Mitigation only Fix from $1,6002026-03-20 MEDIUM 6.3 CVE-2026-4485 A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/search_s… Mitigation only Fix from $1,6002026-03-20 HIGH 7.2 CVE-2026-33133 WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup a… Wegia Patch available Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-33134 WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/… Wegia 3.6.6+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-4473 A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appo… Online Doctor Appointment System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4472 A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the fi… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4469 A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4470 A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of … Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4471 A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_em… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-33025 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_P… Avideo Encoder 8.0+ Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-32950 SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab… Sqlbot 1.7.0+ Fix from $1,9502026-03-20