Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-1177 A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/save_folder.jsp of the… Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1178 A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /kmf/select.jsp of th… Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1176 A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the file /subject/index.php. Per… School Management System Mitigation only Fix from $2,3002026-01-19 HIGH 8.3 CVE-2026-22850 Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped … Koko Analytics 2.1.3+ Fix from $1,9502026-01-19 CRITICAL 9.8 CVE-2026-1160 A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of t… Directory Management System Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-0610 SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12 Devolutions Server 2025.3.14.0+ Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1159 A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This issue affects some unknown processing of the file /order… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1133 A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET … Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1132 A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET … Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1131 A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parame… Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1130 A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP G… Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1129 A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GE… Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1124 A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1123 A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Para… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1120 A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component H… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1121 A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Para… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1122 A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Pa… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1119 A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/delete_activity.p… Society Management System Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1118 A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/add_activity.php. Perf… Society Management System Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1105 A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of … Easycms after 1.6 Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1059 A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknow… Warehouse Management System after 2021-11-15 Fix from $2,3002026-01-17 HIGH 7.3 CVE-2026-1050 A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/r… Mitigation only Fix from $1,9502026-01-17 HIGH 7.2 CVE-2026-23723 WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was identified in the Atendido_ocorr… Wegia 3.6.2+ Fix from $1,9502026-01-16 HIGH 7.8 CVE-2025-61943 The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Hist… Process Optimization 2025+ Fix from $1,9502026-01-16 CRITICAL 9.1 CVE-2021-47811 Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Atta… Grocery Crud 2.0.1+ Fix from $2,3002026-01-16 HIGH 8.2 CVE-2021-47801 Vianeos OctoPUS 5 contains a time-based blind SQL injection vulnerability in the 'login_user' parameter during authentication requests. Attackers can… No fix yet Fix from $1,9502026-01-16 HIGH 8.2 CVE-2021-47782 Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicio… No fix yet Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2025-70892 Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly … Cyber Cafe Management System Mitigation only Fix from $2,3002026-01-15 HIGH 8.8 CVE-2025-70893 A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The appli… Cyber Cafe Management System No fix yet Fix from $1,9502026-01-15 CRITICAL 9.8 CVE-2025-66417 GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven… Glpi 11.0.3+ Fix from $2,3002026-01-15