Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.6 CVE-2026-32358 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind… Mitigation only Fix from $1,9502026-03-13 CRITICAL 9.9 CVE-2026-32306 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregat… Oneuptime 10.0.23+ Fix from $2,3002026-03-13 HIGH 8.5 CVE-2026-31922 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Inject… Mitigation only Fix from $1,9502026-03-13 HIGH 8.5 CVE-2026-31917 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This iss… Mitigation only Fix from $1,9502026-03-13 HIGH 7.3 CVE-2026-25076 Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenticated attacker that is able t… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-22193 wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escapi… Wpdiscuz 7.6.47+ Fix from $1,9502026-03-13 HIGH 7.2 CVE-2025-36368 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vul… Sterling B2b Integrator 6.1.2.8 / 6.2.0.5_2+ Fix from $1,9502026-03-13 HIGH 8.8 CVE-2026-32137 Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly con… Dataease 2.10.20+ Fix from $1,9502026-03-12 HIGH 8.8 CVE-2026-26794 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers… Ar300m16 Firmware No fix yet Fix from $1,9502026-03-12 CRITICAL 9.9 CVE-2026-21708 A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. Veeam Backup \& Replication 12.3.2.4465.+ Fix from $2,3002026-03-12 HIGH 8.2 CVE-2019-25541 Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through … Php Mall No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25542 Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inj… Real Estate Portal No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25543 Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by in… Real Estate Portal No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25537 Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database que… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25538 202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th… 202cms No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25539 202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co… 202cms No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25540 Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injec… Php Mall No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25531 Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to m… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25532 Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25533 Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries b… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25534 Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injectin… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25535 Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting … No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25536 Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries… Real Estate Portal No fix yet Fix from $1,9502026-03-12 CRITICAL 9.1 CVE-2019-25526 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25527 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25528 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 HIGH 7.1 CVE-2019-25529 Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL co… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25530 uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co… No fix yet Fix from $1,9502026-03-12 CRITICAL 9.1 CVE-2019-25521 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25522 XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQ… Xoogallery No fix yet Fix from $2,3002026-03-12