Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.3 CVE-2026-1449 A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XF… Mitigation only Fix from $1,9502026-01-27 HIGH 7.2 CVE-2025-59473 SQL Injection vulnerability in the Structure for Admin authenticated user Expressionengine 7.5.14+ Fix from $1,9502026-01-26 CRITICAL 9.8 CVE-2026-1443 A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/Adm… Online Music Site Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1422 A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /ind… Online Examination System Mitigation only Fix from $2,3002026-01-26 MEDIUM 6.8 CVE-2025-14973 The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing cont… Mitigation only Fix from $1,6002026-01-26 CRITICAL 9.4 CVE-2025-52025 An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulner… Gemscms Backend after 2025-05-28 Fix from $2,3002026-01-23 HIGH 7.6 CVE-2026-24624 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL I… Mitigation only Fix from $1,9502026-01-23 HIGH 8.5 CVE-2026-24572 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio Content nelio-content allo… Mitigation only Fix from $1,9502026-01-23 HIGH 8.3 CVE-2026-0603 A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially … Mitigation only Fix from $1,9502026-01-23 HIGH 8.5 CVE-2026-24367 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL I… Mitigation only Fix from $1,9502026-01-22 HIGH 7.6 CVE-2026-22470 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real E… Mitigation only Fix from $1,9502026-01-22 HIGH 8.5 CVE-2025-69180 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra Portfolio ultra-portfolio al… Mitigation only Fix from $1,9502026-01-22 HIGH 8.5 CVE-2025-69045 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FooEvents FooEvents for WooCommerce fooevents a… Mitigation only Fix from $1,9502026-01-22 HIGH 8.5 CVE-2025-68999 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-e… Mitigation only Fix from $1,9502026-01-22 HIGH 8.5 CVE-2025-68881 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Inj… Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.3 CVE-2025-68857 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Downloads paid-downloads allows … Mitigation only Fix from $2,3002026-01-22 HIGH 7.5 CVE-2025-68017 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Email Validator antideo-email-v… Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.3 CVE-2025-68034 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp all… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-67945 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration… Mitigation only Fix from $2,3002026-01-22 HIGH 8.5 CVE-2025-49049 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allow… Mitigation only Fix from $1,9502026-01-22 HIGH 8.5 CVE-2025-49050 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca… Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.3 CVE-2025-49055 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca… Mitigation only Fix from $2,3002026-01-22 HIGH 8.8 CVE-2025-36588 Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') … Unisphere For Powermax 9.2.4.19+ Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-4764 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel… Hotel Guest Hotspot after 2026-01-22 Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2025-27378 AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this … On Prem Enterprise Server 7.0.6+ Fix from $2,3002026-01-22 HIGH 7.1 CVE-2021-47872 SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipula… No fix yet Fix from $1,9502026-01-21 HIGH 8.2 CVE-2021-47848 Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username p… No fix yet Fix from $1,9502026-01-21 HIGH 8.2 CVE-2021-47846 Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated… No fix yet Fix from $1,9502026-01-21 MEDIUM 6.5 CVE-2025-67261 Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the Ord… Retail Point Of Sale Mitigation only Fix from $1,6002026-01-20 CRITICAL 9.8 CVE-2026-1179 A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter H… Ksoa Mitigation only Fix from $2,3002026-01-19