Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.3 CVE-2026-2247 SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote a… Mitigation only Fix from $1,9502026-02-17 MEDIUM 6.3 CVE-2026-2553 A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown pa… Mitigation only Fix from $1,6002026-02-16 HIGH 7.5 CVE-2026-2024 The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due… Mitigation only Fix from $1,9502026-02-14 CRITICAL 9.8 CVE-2025-69633 A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7… Mitigation only Fix from $2,3002026-02-13 HIGH 7.5 CVE-2019-25335 PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers c… No fix yet Fix from $1,9502026-02-12 HIGH 8.2 CVE-2019-25325 Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authenti… No fix yet Fix from $1,9502026-02-12 MEDIUM 6.5 CVE-2019-25320 E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by mani… No fix yet Fix from $1,6002026-02-12 HIGH 7.5 CVE-2019-25346 TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Atta… Password Management Application No fix yet Fix from $1,9502026-02-12 HIGH 7.5 CVE-2019-25347 thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attac… Password Management Application No fix yet Fix from $1,9502026-02-12 MEDIUM 6.5 CVE-2026-22821 mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4. More Reporting 1.9.4+ Fix from $1,6002026-02-12 CRITICAL 9.8 CVE-2025-70981 CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter. Cordys Crm Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-10969 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Com… E Commerce Package after 2025-11-27 Fix from $2,3002026-02-12 MEDIUM 6.5 CVE-2025-13431 The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all versions up to, and including, … Mitigation only Fix from $1,6002026-02-11 HIGH 8.8 CVE-2026-25947 Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construc… Worklenz 2.1.7+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2026-25993 EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path val… Evershop after 2.1.0 Fix from $2,3002026-02-10 MEDIUM 6.5 CVE-2026-1602 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002026-02-10 HIGH 8.8 CVE-2025-7636 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security Systems Computer Industry and … Mitigation only Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-2093 Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read … Mitigation only Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-2094 Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, m… Mitigation only Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-25495 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/g… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2025-6830 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Passw… Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2225 A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component … News Portal Project Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2223 A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the f… Online Reviewer System Mitigation only Fix from $2,3002026-02-09 MEDIUM 6.5 CVE-2026-2235 C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read databa… Mitigation only Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-2236 C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read dat… Mitigation only Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-2220 A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assess… Online Reviewer System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2221 A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the … Online Reviewer System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2217 A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php… Event Management System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2211 A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCate… Online Music Site Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2212 A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Admini… Online Music Site Mitigation only Fix from $2,3002026-02-09