Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.2 CVE-2021-47777 Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attacke… No fix yet Fix from $1,9502026-01-15 HIGH 7.1 CVE-2021-47766 Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipula… No fix yet Fix from $1,9502026-01-15 HIGH 8.2 CVE-2021-47763 Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries… No fix yet Fix from $1,9502026-01-15 MEDIUM 6.5 CVE-2025-67082 An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a repo… Invoiceplane 1.6.4+ Fix from $1,6002026-01-15 HIGH 7.5 CVE-2025-12166 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `ord… Mitigation only Fix from $1,9502026-01-14 HIGH 7.2 CVE-2025-37182 Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL … Edgeconnect Sd Wan Orchestrator 9.5.6+ Fix from $1,9502026-01-14 HIGH 7.2 CVE-2025-37183 Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL … Edgeconnect Sd Wan Orchestrator 9.5.6+ Fix from $1,9502026-01-14 HIGH 7.2 CVE-2025-37181 Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL … Edgeconnect Sd Wan Orchestrator 9.5.6+ Fix from $1,9502026-01-14 MEDIUM 5.3 CVE-2025-66169 Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before… Camel 4.10.8 / 4.14.3+ Fix from $1,6002026-01-14 HIGH 7.5 CVE-2025-14770 The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions up to, and including, 2.0.0 … Mitigation only Fix from $1,9502026-01-14 HIGH 8.2 CVE-2023-54340 WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and passwor… No fix yet Fix from $1,9502026-01-13 HIGH 8.2 CVE-2023-54333 Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database q… No fix yet Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2022-50894 VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting … Wallpaper Admin No fix yet Fix from $1,6002026-01-13 CRITICAL 9.8 CVE-2022-50895 Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exp… Aerocms Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50892 VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials.… Wallpaper Admin Mitigation only Fix from $2,3002026-01-13 HIGH 8.2 CVE-2022-50805 Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL… No fix yet Fix from $1,9502026-01-13 HIGH 8.8 CVE-2026-20947EPSS 19% Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19127.20442+ Fix from $1,9502026-01-13 HIGH 7.2 CVE-2025-59922EPSS 7% An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientE… Forticlientems 7.2.12 / 7.4.5+ Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2025-69991 phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. News Portal No fix yet Fix from $2,3002026-01-13 HIGH 8.8 CVE-2025-13774 A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to… Flowmon Anomaly Detection System after 13.0.1 Fix from $1,9502026-01-13 CRITICAL 9.9 CVE-2026-0501 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute cra… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.4 CVE-2025-67146 Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) train… Gym Management System No fix yet Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-67147 Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1… Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.1 CVE-2025-51567 A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary… Online Exam System No fix yet Fix from $2,3002026-01-12 HIGH 8.7 CVE-2025-41005 Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’. Mitigation only Fix from $1,9502026-01-12 CRITICAL 9.3 CVE-2025-41006 Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. Mitigation only Fix from $2,3002026-01-12 HIGH 8.7 CVE-2025-41004 Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’… Mitigation only Fix from $1,9502026-01-12 CRITICAL 9.8 CVE-2025-52694EPSS 38% Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vu… Iot Edge Linux Docker 2.0.2 / 3.4.15+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-0852 A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH… Online Music Site Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-0851 A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/Adm… Online Music Site Mitigation only Fix from $2,3002026-01-12