Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-30860 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution… Weknora 0.2.12+ Fix from $2,3002026-03-07 HIGH 7.5 CVE-2025-14353 The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcod… Mitigation only Fix from $1,9502026-03-07 CRITICAL 9.8 CVE-2018-25199 OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious … Php Oop Cms Blog Mitigation only Fix from $2,3002026-03-06 HIGH 8.2 CVE-2018-25192 GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25196 ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25197 PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious… No fix yet Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2018-25187 Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection a… Tina4 Stack Mitigation only Fix from $2,3002026-03-06 HIGH 8.2 CVE-2018-25188 Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25189 Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to e… No fix yet Fix from $1,9502026-03-06 HIGH 7.1 CVE-2018-25191 Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting mali… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25179 Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious … No fix yet Fix from $1,9502026-03-06 HIGH 7.1 CVE-2018-25180 Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25182 Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inje… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25175 Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25172 Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious cod… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25173 Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code th… No fix yet Fix from $1,9502026-03-06 HIGH 7.1 CVE-2018-25165 Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting … No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25166 Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25167 Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute … No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25163 BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious cod… No fix yet Fix from $1,9502026-03-06 HIGH 8.2 CVE-2018-25161 Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting maliciou… No fix yet Fix from $1,9502026-03-06 HIGH 8.8 CVE-2026-29073 SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic a… Siyuan after 3.5.9 Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-28438 CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name befo… Cocoindex 0.3.34+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28785 Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary … Ghostfolio 2.244.0+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-27005 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3… Chartbrew 4.8.3+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28501 WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec… Avideo 24.0+ Fix from $2,3002026-03-06 MEDIUM 6.3 CVE-2026-3616 A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modu… Patch available Fix from $1,6002026-03-06 CRITICAL 9.8 CVE-2026-28443 OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sor… Openreplay 1.20.0+ Fix from $2,3002026-03-05 HIGH 8.8 CVE-2026-29081 Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specia… Frappe 14.100.1+ Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-28210 FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. T… Freepbx 16.0.49 / 17.0.7+ Fix from $1,9502026-03-05