Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-31877 Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i… Frappe 14.99.0 / 15.84.0+ Fix from $2,3002026-03-11 HIGH 8.2 CVE-2019-25486 Varient 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro… No fix yet Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-31871 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL inje… Parse Server 8.6.31 / 9.6.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31856 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the P… Parse Server 8.6.29 / 9.6.0+ Fix from $2,3002026-03-11 HIGH 8.8 CVE-2026-31858 Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to … Craft Cms 5.9.9+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-31840 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacke… Parse Server 8.6.28 / 9.6.0+ Fix from $2,3002026-03-11 HIGH 7.5 CVE-2026-3496 The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up to, and including, 4.0.3. Thi… Mitigation only Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-3944 A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /att_add.php. Th… University Management System Mitigation only Fix from $2,3002026-03-11 HIGH 7.5 CVE-2026-1708 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versi… Mitigation only Fix from $1,9502026-03-11 MEDIUM 6.7 CVE-2024-14025 An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administr… Video Station 5.8.2+ Fix from $1,6002026-03-11 HIGH 8.8 CVE-2026-31844 An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due t… Koha 24.11.12 / 25.05.07+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-3222 The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including… Mitigation only Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-2413 The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4… Mitigation only Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-31825 Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user… Sylius 1.9.12 / 1.10.16+ Fix from $1,6002026-03-10 HIGH 7.5 CVE-2026-30951 Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverse… Sequelize 6.37.8+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-29172 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables t… Craft Commerce 4.10.2 / 5.5.3+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-29174 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table da… Craft Commerce 5.5.3+ Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2026-3843 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuratio… Buk Ts G Gas Station Automation System 2.10.2+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-30930 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string co… Glances 4.5.1+ Fix from $2,3002026-03-10 HIGH 8.8 CVE-2026-26116 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6480.4 / 13.0.7075.5+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2025-56421 SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database. Limesurvey after 6.15.3 Fix from $1,9502026-03-10 HIGH 7.2 CVE-2025-49784 An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, … Fortianalyzer 7.4.5 / 7.4.8+ Fix from $1,9502026-03-10 MEDIUM 6.4 CVE-2026-27684 SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL cod… Mitigation only Fix from $1,6002026-03-10 CRITICAL 9.8 CVE-2026-3818 A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This mani… Easy7 Cms Mitigation only Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2025-40639 A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases thr… Eventobot Mitigation only Fix from $2,3002026-03-09 HIGH 8.8 CVE-2026-3806 A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_r… Resort Reservation System No fix yet Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3793 A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.p… Sales And Inventory System No fix yet Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3792 A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the comp… Sales And Inventory System No fix yet Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3791 A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file das… Sales And Inventory System No fix yet Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3790 A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_… Sales And Inventory System No fix yet Fix from $1,9502026-03-09