Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.1 CVE-2019-25523 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25524 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25525 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25515 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthent… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 HIGH 7.5 CVE-2019-25516 Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie… Php Stock News Site Script No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25517 Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie… Php Stock News Site Script No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25518 Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie… Php Stock News Site Script No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25519 Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting m… Php Stock News Site Script No fix yet Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2019-25520 Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated att… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25510 Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated att… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 HIGH 8.2 CVE-2019-25511 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie… Php Stock News Site Script No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25512 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the … Php Stock News Site Script No fix yet Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2019-25513 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25514 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the … Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 HIGH 8.2 CVE-2019-25479 Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25481 iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL c… No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25482 Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database q… Php Ready Rent A Car Site Script No fix yet Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2019-25488 Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipu… Php Ready Rent A Car Site Script Mitigation only Fix from $2,3002026-03-12 HIGH 8.2 CVE-2019-25508 Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries… Php Ready Advertisement Site Script No fix yet Fix from $1,9502026-03-12 HIGH 8.2 CVE-2019-25509 XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … No fix yet Fix from $1,9502026-03-12 HIGH 7.1 CVE-2019-25473 Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through th… No fix yet Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2026-4014 A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of … Cafe Reservation System Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3981 A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php.… Online Doctor Appointment System Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3980 A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_acti… Online Doctor Appointment System Mitigation only Fix from $2,3002026-03-12 HIGH 7.5 CVE-2026-3657 The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action in all versions up to, and i… Mitigation only Fix from $1,9502026-03-12 HIGH 7.3 CVE-2026-3969 A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of… Mitigation only Fix from $1,9502026-03-12 HIGH 8.8 CVE-2026-32127 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL inj… Openemr 8.0.0.1+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2025-70024 An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14. Mitigation only Fix from $2,3002026-03-11 HIGH 8.8 CVE-2026-31895 WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL in… Wegia 3.6.6+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-31896 WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. T… Wegia 3.6.6+ Fix from $2,3002026-03-11