Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-3068 A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a… Document Management System Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-3057 A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/co… Pearprojectapi after 2.8.10 Fix from $2,3002026-02-24 HIGH 7.5 CVE-2026-26198 Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by pa… Ormar 0.23.0+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-3046 A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unkno… E Logbook With Health Monitoring System For Covid 19 Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-3042 A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. P… Event Management System Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.3 CVE-2025-41002 SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the dat… Mitigation only Fix from $2,3002026-02-23 HIGH 8.3 CVE-2026-1367EPSS 7% Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. Mitigation only Fix from $1,9502026-02-23 CRITICAL 9.8 CVE-2026-24494 SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attack… Mitigation only Fix from $2,3002026-02-23 MEDIUM 6.3 CVE-2026-2963 A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C6/Jhsoft.Web.officesupply/Off… Mitigation only Fix from $1,6002026-02-23 HIGH 7.5 CVE-2019-25461 Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injec… Platinum E Ticaret No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25462 Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL… No fix yet Fix from $1,9502026-02-22 CRITICAL 9.1 CVE-2019-25456 Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code… Emlak No fix yet Fix from $2,3002026-02-22 HIGH 7.5 CVE-2019-25457 Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL cod… Firma No fix yet Fix from $1,9502026-02-22 CRITICAL 9.8 CVE-2019-25458 Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting … Firma Rehberi Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2019-25459 Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database querie… Emlak Mitigation only Fix from $2,3002026-02-22 HIGH 7.5 CVE-2019-25460 Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injec… Platinum E Ticaret No fix yet Fix from $1,9502026-02-22 HIGH 7.5 CVE-2019-25455 Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL … E Ticaret No fix yet Fix from $1,9502026-02-22 HIGH 7.5 CVE-2019-25452 Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated … Dolibarr Erp\/crm No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25440 WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro… No fix yet Fix from $1,9502026-02-22 HIGH 7.5 CVE-2019-25442 Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co… Web Wiz Forums No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25443 Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t… No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25446 DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … No fix yet Fix from $1,9502026-02-22 HIGH 7.5 CVE-2019-25450 Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin… Dolibarr Erp\/crm No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25391 Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the… No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25433 XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th… No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25439 NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code throu… No fix yet Fix from $1,9502026-02-22 HIGH 8.2 CVE-2019-25366 microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mali… No fix yet Fix from $1,9502026-02-22 CRITICAL 9.8 CVE-2026-2912 A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessment… Online Reviewer System Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2026-2867 A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing … Vehicle Management System Mitigation only Fix from $2,3002026-02-21 HIGH 8.8 CVE-2026-27470 ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is … Zoneminder 1.36.38 / 1.38.1+ Fix from $1,9502026-02-21