Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2026-1551 A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/course/controller.php… School Management System No fix yet Fix from $1,9502026-01-29 HIGH 8.8 CVE-2025-15344 Tanium addressed a SQL injection vulnerability in Asset. Asset 1.28.254 / 1.32.161+ Fix from $1,9502026-01-29 CRITICAL 9.8 CVE-2026-1545 A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function of the file /course/index.ph… School Management System Mitigation only Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2026-1546 A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshER… Jsherp after 3.6 Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2026-1534 A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.… Online Music Site Mitigation only Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2026-1535 A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/Ad… Online Music Site Mitigation only Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2026-1533 A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH… Online Music Site Mitigation only Fix from $2,3002026-01-28 CRITICAL 10.0 CVE-2025-57792 Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application e… Blue 8.14.9+ Fix from $2,3002026-01-28 HIGH 8.6 CVE-2025-57793 Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web appl… Blue 8.14.9+ Fix from $1,9502026-01-28 HIGH 7.5 CVE-2020-36972 SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract da… Smartblog No fix yet Fix from $1,9502026-01-28 HIGH 8.2 CVE-2020-36945 WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by… No fix yet Fix from $1,9502026-01-28 HIGH 8.8 CVE-2026-22243 EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to version… Egroupware 23.1.20260113 / 26.0.20260113+ Fix from $1,9502026-01-28 HIGH 7.5 CVE-2026-0702 The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'fields' parameter in all versi… Mitigation only Fix from $1,9502026-01-28 HIGH 7.5 CVE-2026-1477 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1478 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1479 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1480 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1481 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1482 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1483 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1472 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1473 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1474 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1475 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1476 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico… Evaluacion De Desempeno Mitigation only Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2025-69562 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69563 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 HIGH 8.2 CVE-2021-47902 Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q'… No fix yet Fix from $1,9502026-01-27 MEDIUM 6.5 CVE-2020-36947 LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract data… Librenms No fix yet Fix from $1,6002026-01-27 HIGH 8.2 CVE-2020-36951 Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queri… No fix yet Fix from $1,9502026-01-27