Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2026-32954 ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-… Erpnext 15.100.0 / 16.8.0+ Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-32888 Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in t… Open Source Point Of Sale after 3.4.2 Fix from $1,9502026-03-20 HIGH 8.0 CVE-2026-32813 Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configurati… Admidio 5.0.7+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-32767 SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextS… Siyuan 3.6.1+ Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-33288 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL I… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,9502026-03-20 HIGH 8.2 CVE-2026-32763 Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation f… Kysely 0.28.12+ Fix from $1,9502026-03-20 MEDIUM 6.5 CVE-2026-29096 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when cr… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,6002026-03-19 HIGH 8.8 CVE-2026-29099 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `re… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-30711 Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer … Mitigation only Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-3658 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' p… Mitigation only Fix from $1,9502026-03-19 CRITICAL 9.3 CVE-2026-27413 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL… Mitigation only Fix from $2,3002026-03-19 HIGH 7.2 CVE-2026-32698 OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL i… Openproject 16.6.9 / 17.0.6+ Fix from $1,9502026-03-18 HIGH 8.8 CVE-2026-32321 ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5… Clipbucket 5.5.3-80+ Fix from $1,9502026-03-18 HIGH 8.8 CVE-2025-58112 Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an uplo… Mitigation only Fix from $1,9502026-03-18 CRITICAL 9.1 CVE-2026-32611 Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export… Glances 4.5.2+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2025-67830 Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. Mura Cms 10.1.4+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2025-67829 Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. Mura Cms 10.1.4+ Fix from $2,3002026-03-18 HIGH 8.8 CVE-2026-22730 A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and … Spring Ai 1.0.4 / 1.1.3+ Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2026-33058 Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. At… Kanboard 1.2.51+ Fix from $1,6002026-03-18 MEDIUM 6.5 CVE-2026-31891 Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially af… Cockpit 2.13.5+ Fix from $1,6002026-03-18 HIGH 8.8 CVE-2026-26001 The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitiz… Glpi Inventory 1.6.6+ Fix from $1,9502026-03-18 HIGH 8.8 CVE-2026-25936 GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a S… Glpi after 11.0.6 Fix from $1,9502026-03-17 CRITICAL 9.8 CVE-2026-4319 A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file … Simple Food Order System Mitigation only Fix from $2,3002026-03-17 MEDIUM 5.4 CVE-2026-4324 A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a re… Mitigation only Fix from $1,6002026-03-17 HIGH 7.5 CVE-2026-2579 The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all v… Mitigation only Fix from $1,9502026-03-17 HIGH 7.3 CVE-2026-4287 A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /r… Mitigation only Fix from $1,9502026-03-17 HIGH 7.3 CVE-2026-4288 A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/d… Mitigation only Fix from $1,9502026-03-17 HIGH 7.3 CVE-2026-4289 A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file … Mitigation only Fix from $1,9502026-03-17 HIGH 8.8 CVE-2026-30881 Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The pa… Chamilo Lms 1.11.36+ Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2026-28430 Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote at… Chamilo Lms 1.11.34+ Fix from $2,3002026-03-16