Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2025-69768 SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component Chyrp after 2.5.2 Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2025-62319 Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE… Unica 25.1.1.0.1+ Fix from $2,3002026-03-16 MEDIUM 5.3 CVE-2025-52646 HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper valid… Aion 2.1.2+ Fix from $1,6002026-03-16 MEDIUM 6.3 CVE-2026-4241 A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/time-tab… Mitigation only Fix from $1,6002026-03-16 HIGH 7.3 CVE-2026-4237 A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4232 A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /res… Mitigation only Fix from $1,9502026-03-16 MEDIUM 6.3 CVE-2026-4234 A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component… Mitigation only Fix from $1,6002026-03-16 HIGH 7.3 CVE-2026-4235 A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. T… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4236 A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/inde… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4229 A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vect… Mitigation only Fix from $1,9502026-03-16 MEDIUM 6.3 CVE-2026-4230 A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/legacy/flask/__init__.py of t… Mitigation only Fix from $1,6002026-03-16 CRITICAL 9.8 CVE-2026-4223 A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee… Payroll Management System Mitigation only Fix from $2,3002026-03-16 HIGH 7.3 CVE-2026-4190 A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulat… Mitigation only Fix from $1,9502026-03-16 MEDIUM 6.3 CVE-2026-4173 A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. This vulnerability affects the function exportTable/exportTableColumnComment/exportView/exp… Mitigation only Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2026-3021 Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/emplea… Wakyma Mitigation only Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2026-3022 Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/gene… Wakyma Mitigation only Fix from $1,6002026-03-16 HIGH 8.8 CVE-2026-3023 Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. Th… Wakyma Mitigation only Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-32628 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a … Anythingllm after 1.11.1 Fix from $1,9502026-03-16 HIGH 7.3 CVE-2025-52637 HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper valid… Aion 2.1.2+ Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2015-20121 Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by … Realtyscript Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2015-20120 Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra… Realtyscript Mitigation only Fix from $2,3002026-03-16 HIGH 7.6 CVE-2026-32458 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL In… Mitigation only Fix from $1,9502026-03-13 HIGH 7.6 CVE-2026-32459 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bump… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-32433 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-conta… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-32422 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart al… Mitigation only Fix from $1,9502026-03-13 HIGH 7.6 CVE-2026-32418 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Bli… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-32399 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-lib… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-32368 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-32365 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archive… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-32366 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categ… Mitigation only Fix from $1,9502026-03-13