Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.6 CVE-2026-46593 A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminP… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.3 CVE-2025-67649 A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into paramet… No fix yet Fix from $2,3002026-07-31 HIGH 8.6 CVE-2025-67650 An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an aut… No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-15258 The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before… No fix yet Fix from $1,9502026-07-31 HIGH 8.6 CVE-2026-12721 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, al… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-14554 The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing use… No fix yet Fix from $1,6002026-07-31 CRITICAL 9.4 CVE-2026-63221 CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2025-69931 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69933 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69934 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69935 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69936 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69937 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69938 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69941 SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69947 SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69930 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-65336 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-4978 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL … No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-54368 CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to e… Mitigation only Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-17543 Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from… PHP 8.2.33 / 8.3.33+ Fix from $2,3002026-07-30 HIGH 8.6 CVE-2026-22620 Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker t… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.9 CVE-2026-58046 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data f… No fix yet Fix from $2,3002026-07-30 MEDIUM 6.8 CVE-2026-15153 The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a … No fix yet Fix from $1,6002026-07-30 HIGH 8.6 CVE-2026-13395 The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from … No fix yet Fix from $1,9502026-07-30 HIGH 8.6 CVE-2026-48448 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… Campaign after 7.4.2 Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-16092 The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action… No fix yet Fix from $1,6002026-07-30 HIGH 7.1 CVE-2026-15929 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.… No fix yet Fix from $1,9502026-07-30 HIGH 7.3 CVE-2025-69945 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-69949 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email. No fix yet Fix from $1,9502026-07-29