Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 5.4 CVE-2026-1312 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column a… Django 4.2.28 / 5.2.11+ Fix from $1,6002026-02-03 CRITICAL 9.8 CVE-2025-5319 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.3 CVE-2026-1432 SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vulnerability is present in sever… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-8587 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade… Skspro after 2026-07-01 Fix from $2,3002026-02-02 HIGH 8.8 CVE-2026-1746 A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of th… Jeecg Boot No fix yet Fix from $1,9502026-02-02 HIGH 8.8 CVE-2021-47918 Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. … Simple Cms Php No fix yet Fix from $1,9502026-02-01 HIGH 8.8 CVE-2021-47915 PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious… Php Melody No fix yet Fix from $1,9502026-02-01 HIGH 8.1 CVE-2021-47909 Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with pri… Mitigation only Fix from $1,9502026-02-01 MEDIUM 6.5 CVE-2026-0683 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the Number-type custom field fil… Mitigation only Fix from $1,6002026-01-31 MEDIUM 6.5 CVE-2020-37053 Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx… Navigate Cms No fix yet Fix from $1,6002026-01-30 CRITICAL 9.8 CVE-2020-37057 Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through th… Online Exam System Mitigation only Fix from $2,3002026-01-30 MEDIUM 5.3 CVE-2020-37051 Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database passwo… Online Exam System No fix yet Fix from $1,6002026-01-30 HIGH 8.2 CVE-2020-37033 Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter… No fix yet Fix from $1,9502026-01-30 HIGH 8.2 CVE-2020-37035 e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries t… No fix yet Fix from $1,9502026-01-30 HIGH 8.6 CVE-2025-69662 SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used … Geopandas 1.1.2+ Fix from $1,9502026-01-30 CRITICAL 9.8 CVE-2026-1701 A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enro… School Management System Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2026-1688 A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /… Directory Management System Mitigation only Fix from $2,3002026-01-30 HIGH 8.8 CVE-2026-24854 ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to v… Churchcrm 6.7.2+ Fix from $1,9502026-01-30 HIGH 8.6 CVE-2025-4686 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction… Mitigation only Fix from $1,9502026-01-30 CRITICAL 9.8 CVE-2026-1595 A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. T… Society Management System Mitigation only Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1589 A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php… School Management System Mitigation only Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1590 A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php… School Management System Mitigation only Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1593 A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … Society Management System Mitigation only Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1594 A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the… Society Management System Mitigation only Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2025-7714 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive Design Media Software Inc. C… Content Management System after 2025-07-21 Fix from $2,3002026-01-29 HIGH 8.2 CVE-2020-37004 The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and passwo… No fix yet Fix from $1,9502026-01-29 HIGH 7.1 CVE-2020-37005 TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipu… No fix yet Fix from $1,9502026-01-29 HIGH 8.2 CVE-2020-37006 berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Att… No fix yet Fix from $1,9502026-01-29 HIGH 8.2 CVE-2020-36999 Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL… No fix yet Fix from $1,9502026-01-29 CRITICAL 9.8 CVE-2026-1552 A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of t… Semcms Mitigation only Fix from $2,3002026-01-29