Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.2 CVE-2026-0850 A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_ac… Intern Membership Management System No fix yet Fix from $1,9502026-01-11 MEDIUM 6.3 CVE-2026-0843 A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerability affects unknown code of t… Mitigation only Fix from $1,6002026-01-11 CRITICAL 10.0 CVE-2025-65091 XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONServi… Full Calendar Macro 2.4.5+ Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2026-22687 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables th… Weknora 0.2.5+ Fix from $2,3002026-01-10 HIGH 7.2 CVE-2026-22596 Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admi… Ghost 5.130.6 / 6.11.0+ Fix from $1,9502026-01-10 MEDIUM 6.5 CVE-2025-51626 SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint. Pss.sale.com Mitigation only Fix from $1,6002026-01-09 MEDIUM 6.5 CVE-2025-67811 Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient input validation allows remote … Rhapsode Mitigation only Fix from $1,6002026-01-09 HIGH 8.1 CVE-2026-22196 GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket… Gestsup after 3.2.56 Fix from $1,9502026-01-09 HIGH 8.1 CVE-2026-22197 GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to … Gestsup after 3.2.56 Fix from $1,9502026-01-09 HIGH 8.1 CVE-2026-22195 GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated … Gestsup after 3.2.56 Fix from $1,9502026-01-09 HIGH 8.8 CVE-2025-15494 A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. T… Docsys after 2.02.37 Fix from $1,9502026-01-09 CRITICAL 9.8 CVE-2025-15496 A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of th… Yshopmall after 1.9.1 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15493 A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMa… Docsys after 2.02.36 Fix from $2,3002026-01-09 MEDIUM 5.4 CVE-2025-67281 In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access… Tim Flow 9.1.2+ Fix from $1,6002026-01-09 HIGH 8.8 CVE-2026-0803 A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipu… Online Course Registration System after 3.1 Fix from $1,9502026-01-09 HIGH 8.8 CVE-2025-15492 A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/Grou… Docsys after 2.02.36 Fix from $1,9502026-01-09 CRITICAL 9.8 CVE-2025-14598 BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables ar… Bet E Portal Mitigation only Fix from $2,3002026-01-09 HIGH 7.5 CVE-2025-64092 This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database. Icx500 Firmware 1.4.3.3+ Fix from $1,9502026-01-09 HIGH 8.8 CVE-2026-0733 A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/… Online Course Registration System after 3.1 Fix from $1,9502026-01-09 HIGH 7.2 CVE-2026-0729 A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_… Intern Membership Management System No fix yet Fix from $1,9502026-01-08 HIGH 7.2 CVE-2026-0728 A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of th… Intern Membership Management System No fix yet Fix from $1,9502026-01-08 CRITICAL 9.8 CVE-2025-61246 indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter. Online Shopping System Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-61548 SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions… Print Shop Pro Webdesk Mitigation only Fix from $2,3002026-01-08 HIGH 7.3 CVE-2026-21892 Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. … Parsl 2026.01.05+ Fix from $1,9502026-01-08 HIGH 8.5 CVE-2025-67921 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.… Mitigation only Fix from $1,9502026-01-08 CRITICAL 9.3 CVE-2025-67928 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allow… Mitigation only Fix from $2,3002026-01-08 HIGH 8.5 CVE-2025-22728 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap a… Mitigation only Fix from $1,9502026-01-08 CRITICAL 9.3 CVE-2025-23993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allow… Mitigation only Fix from $2,3002026-01-08 HIGH 8.5 CVE-2025-22713 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporte… Mitigation only Fix from $1,9502026-01-08 HIGH 7.2 CVE-2026-0701 A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality o… Intern Membership Management System No fix yet Fix from $1,9502026-01-08