Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-3406 A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p… Online Art Gallery Shop Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-28562 wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql… Wpforo Forum 2.4.15+ Fix from $2,3002026-02-28 HIGH 7.5 CVE-2025-13673 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versi… Mitigation only Fix from $1,9502026-02-28 HIGH 8.8 CVE-2026-28516 openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-ins… Opendcim Patch available Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-27832 Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injectio… Group Office 6.8.153 / 25.0.87+ Fix from $1,9502026-02-27 HIGH 8.2 CVE-2019-25494 Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication… Airbnb Clone Script No fix yet Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25495 osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Oscommerce No fix yet Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25496 osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Oscommerce No fix yet Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25497 osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Oscommerce after 2.3.4.1 Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25490 Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug… Airbnb Clone Script No fix yet Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25491 Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu… Airbnb Clone Script No fix yet Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25492 Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu… Airbnb Clone Script No fix yet Fix from $1,9502026-02-27 HIGH 7.5 CVE-2019-25493 Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu… Airbnb Clone Script No fix yet Fix from $1,9502026-02-27 CRITICAL 9.1 CVE-2019-25489 Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug… Airbnb Clone Script No fix yet Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2751 Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S… Centreon Web 24.04.24. / 24.10.20+ Fix from $2,3002026-02-27 CRITICAL 9.3 CVE-2025-15498 Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to b… Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2025-11252 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. W… Windesk.fm after 27022026 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2025-11251 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Comm… Woyio Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-3287 A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m… Youlai Mall Mitigation only Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-3292 A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the compon… Jizhicms after 2.5.6 Fix from $1,9502026-02-27 MEDIUM 6.5 CVE-2026-28226 Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL injection vulnerability exists … Phishing Club 1.30.2+ Fix from $1,6002026-02-26 CRITICAL 9.8 CVE-2026-3261 A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component… School Management System Mitigation only Fix from $2,3002026-02-26 MEDIUM 6.5 CVE-2026-27149 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in PM tag filtering (`list_privat… Discourse 2025.12.2 / 2026.1.1+ Fix from $1,6002026-02-26 HIGH 8.8 CVE-2026-22206 SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by… Spip 4.4.10+ Fix from $1,9502026-02-26 HIGH 8.6 CVE-2026-1198 SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated… Mitigation only Fix from $1,9502026-02-26 HIGH 7.6 CVE-2026-28136 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.T… Mitigation only Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-26186 Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbi… Fleet 4.80.1+ Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-27497 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or… N8n 1.123.22 / 2.9.3+ Fix from $1,9502026-02-25 HIGH 7.3 CVE-2026-3200 A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /s… Mitigation only Fix from $1,9502026-02-25 HIGH 8.8 CVE-2026-25746 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL inject… Openemr 8.0.0+ Fix from $1,9502026-02-25