Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2026-2232 The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in … Mitigation only Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-1581 The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.1… Mitigation only Fix from $1,9502026-02-19 HIGH 8.8 CVE-2025-15560 An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If… Worktime after 11.8.8 Fix from $1,9502026-02-19 HIGH 7.6 CVE-2026-25418 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection… Mitigation only Fix from $1,9502026-02-19 HIGH 7.6 CVE-2026-25378 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testin… Mitigation only Fix from $1,9502026-02-19 HIGH 7.6 CVE-2026-23805 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-… Mitigation only Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-2706 A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This ma… Patient Record Management System No fix yet Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-2689 A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The … Event Management System Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2690 A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax… Event Management System Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2691 A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/m… Event Management System Mitigation only Fix from $2,3002026-02-19 MEDIUM 6.5 CVE-2026-0722 The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the… Mitigation only Fix from $1,6002026-02-19 HIGH 7.5 CVE-2025-12707 The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1… Mitigation only Fix from $1,9502026-02-19 MEDIUM 6.7 CVE-2025-15585 Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploi… Mitigation only Fix from $1,6002026-02-19 CRITICAL 9.8 CVE-2026-2682 A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /… Electronic Archives System after 3.2.210802 Fix from $2,3002026-02-18 MEDIUM 5.3 CVE-2025-12812 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Rem… No fix yet Fix from $1,6002026-02-18 CRITICAL 9.8 CVE-2026-27179 MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php fil… Majordomo Patch available Fix from $2,3002026-02-18 MEDIUM 6.3 CVE-2026-2663 A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown processing of the file /frontend-… Mitigation only Fix from $1,6002026-02-18 CRITICAL 9.8 CVE-2025-70152 code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.p… Scholars Tracking System Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-70149 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. Membership Management System Mitigation only Fix from $2,3002026-02-18 HIGH 8.6 CVE-2025-59920 When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If the query URL is copied and … Mitigation only Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2026-1317 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.3… Mitigation only Fix from $1,6002026-02-18 HIGH 7.5 CVE-2026-2495 The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable to SQL Injection via the 'ord… Mitigation only Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2026-1639 The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order'… Mitigation only Fix from $1,6002026-02-18 HIGH 7.5 CVE-2026-2576 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'paymen… Mitigation only Fix from $1,9502026-02-18 HIGH 7.3 CVE-2026-2621 A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the… Mitigation only Fix from $1,9502026-02-17 HIGH 7.3 CVE-2026-2620 A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /We… Mitigation only Fix from $1,9502026-02-17 HIGH 7.6 CVE-2025-67102 A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands vi… Jorani after 1.0.4 Fix from $1,9502026-02-17 HIGH 8.8 CVE-2024-55270 phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter. Student Management System No fix yet Fix from $1,9502026-02-17 HIGH 7.2 CVE-2025-70397 jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter. Jizhicms No fix yet Fix from $1,9502026-02-17 HIGH 8.6 CVE-2025-7631 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Informati… Mitigation only Fix from $1,9502026-02-17