Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.3 CVE-2026-18970 A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of t… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-18958 A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bc… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-10716 Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71287 Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letter… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71288 Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-named parameter, and concatenates… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-71292 Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request paramete… No fix yet Fix from $1,9502026-08-05 HIGH 7.1 CVE-2026-71276 Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and … No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71282 ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpolates the user-supplied tag KE… No fix yet Fix from $1,6002026-08-05 HIGH 7.1 CVE-2026-71245 Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with Inp… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-71248 Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71237 Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71231 IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71207 The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly… No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-18881 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` paramet… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-11977 The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-15281 The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-49004 The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens … No fix yet Fix from $1,6002026-08-05 CRITICAL 9.1 CVE-2026-15360 The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthen… No fix yet Fix from $2,3002026-08-05 MEDIUM 6.5 CVE-2026-11421 The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilt… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-15918 VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls h… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-15941 The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. … No fix yet Fix from $1,6002026-08-05 MEDIUM 6.3 CVE-2026-18896 A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/ch… No fix yet Fix from $1,6002026-08-05 HIGH 7.3 CVE-2026-18859 A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such … No fix yet Fix from $1,9502026-08-05 HIGH 7.3 CVE-2026-18854 A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClas… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-69704 Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET pa… No fix yet Fix from $1,6002026-08-04 HIGH 8.5 CVE-2026-64631 A vulnerability allowing a low-privileged user to inject SQL and extract database contents. No fix yet Fix from $1,9502026-08-04 MEDIUM 6.3 CVE-2026-18766 A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of … No fix yet Fix from $1,6002026-08-04 HIGH 8.8 CVE-2026-70372 Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the qu… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-70373 Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-contro… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-70369 Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parame… No fix yet Fix from $1,9502026-08-04