Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2026-70370 Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directl… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-70371 Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the … No fix yet Fix from $1,9502026-08-04 MEDIUM 6.8 CVE-2026-14872 The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before usin… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.3 CVE-2026-18719 A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a man… No fix yet Fix from $1,6002026-08-04 CRITICAL 9.9 CVE-2026-48326 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-48330 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-69240 Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function define… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-51775 SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.… No fix yet Fix from $2,3002026-08-03 HIGH 8.1 CVE-2026-52521 A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the Comment… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-18737 Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an un… No fix yet Fix from $1,6002026-08-03 HIGH 8.8 CVE-2026-41453 Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to injec… Mitigation only Fix from $1,9502026-08-03 CRITICAL 10.0 CVE-2026-69083 SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and… No fix yet Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-69084 SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr… No fix yet Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-69085 SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is … No fix yet Fix from $2,3002026-08-03 HIGH 8.6 CVE-2026-16572 The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthen… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.1 CVE-2026-16532 The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u… Mitigation only Fix from $2,3002026-08-03 HIGH 8.1 CVE-2026-16539 The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.1 CVE-2026-12965 The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, a… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-65321 PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper … No fix yet Fix from $2,3002026-08-02 HIGH 8.2 CVE-2026-14920 ## Summary No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-6453 The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient inpu… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.5 CVE-2026-16087 The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Par… No fix yet Fix from $1,6002026-08-01 MEDIUM 5.3 CVE-2026-15018 The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versio… No fix yet Fix from $1,6002026-08-01 CRITICAL 9.1 CVE-2026-13596 The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL qu… Mitigation only Fix from $2,3002026-08-01 MEDIUM 5.5 CVE-2026-45376 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organ… No fix yet Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2025-69948 SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2025-69946 SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.4 CVE-2026-58048 Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. No fix yet Fix from $2,3002026-07-31 CRITICAL 9.0 CVE-2026-17351 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlpar… Pgadmin 4 9.17+ Fix from $2,3002026-07-31 HIGH 8.8 CVE-2026-17346 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but miss… Pgadmin 4 9.17+ Fix from $1,9502026-07-31