Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Mjobtime CRITICAL 9.8
CVE-2025-51683

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POS…

Mitigation only
Fix from $2,300 2025-12-01
Blood Bank Management System HIGH 8.8
CVE-2025-63535

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize…

Mitigation only
Fix from $1,950 2025-12-01
Blood Bank Management System HIGH 8.8
CVE-2025-63532

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanit…

Mitigation only
Fix from $1,950 2025-12-01
Blood Bank Management System CRITICAL 9.8
CVE-2025-63531

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properl…

Mitigation only
Fix from $2,300 2025-12-01
Webstack Guns HIGH 7.2
CVE-2025-13811

A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/…

No fix yet
Fix from $1,950 2025-12-01
Chanjet Crm CRITICAL 9.8
CVE-2025-13788

A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. Th…

Fix: after 2025-11-06
Fix from $2,300 2025-11-30
Wtcms CRITICAL 9.8
CVE-2025-13783

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of…

Fix: after 2019-12-20
Fix from $2,300 2025-11-30
Wtcms CRITICAL 9.8
CVE-2025-13782

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the f…

Fix: after 2019-12-20
Fix from $2,300 2025-11-30
Webitr MEDIUM 6.5
CVE-2025-13769

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read databa…

Fix: 2_1_0_34+
Fix from $1,600 2025-11-28
Webitr MEDIUM 6.5
CVE-2025-13770

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read databa…

Fix: 2_1_0_34+
Fix from $1,600 2025-11-28
Devolutions Server HIGH 8.8
CVE-2025-13757

SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.

Fix: 2025.2.21.0 / 2025.3.10.0+
Fix from $1,950 2025-11-27
Frappe Crm HIGH 8.8
CVE-2025-11461

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. Thi…

Patch available
Fix from $1,950 2025-11-26
Ussd Gateway CRITICAL 9.8
CVE-2025-65236

OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpan…

Mitigation only
Fix from $2,300 2025-11-26
Ussd Gateway CRITICAL 9.8
CVE-2025-65235

OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSu…

Mitigation only
Fix from $2,300 2025-11-26
Hive MEDIUM 5.4
CVE-2025-62728

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i…

Mitigation only
Fix from $1,600 2025-11-26
Mozart Next 100 Firmware MEDIUM 6.5
CVE-2025-66260

PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000…

No fix yet
Fix from $1,600 2025-11-26
Pmb MEDIUM 6.5
CVE-2025-61167

SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.9
CVE-2025-59369

A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 6.5
CVE-2025-10144

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortc…

Mitigation only
Fix from $1,600 2025-11-24
Wbrm HIGH 7.6
CVE-2025-56401

ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.

No fix yet
Fix from $1,950 2025-11-24
Online Student Clearance System HIGH 7.2
CVE-2025-13586

A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. T…

No fix yet
Fix from $1,950 2025-11-24
Covid Tracking System CRITICAL 9.8
CVE-2025-13585

A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipu…

Mitigation only
Fix from $2,300 2025-11-24
Unclassified HIGH 7.5
CVE-2025-7402

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘site_id’ par…

Mitigation only
Fix from $1,950 2025-11-24
Question Paper Generator CRITICAL 9.8
CVE-2025-13583

A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the compo…

Mitigation only
Fix from $2,300 2025-11-24
Student Information System HIGH 8.8
CVE-2025-13581

A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file…

No fix yet
Fix from $1,950 2025-11-24
Jonnys Liquor CRITICAL 9.8
CVE-2025-13582

A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functionality of the file /detail.php …

Mitigation only
Fix from $2,300 2025-11-24
Library System CRITICAL 9.8
CVE-2025-13578

A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. T…

Mitigation only
Fix from $2,300 2025-11-24
Library System HIGH 8.8
CVE-2025-13579

A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argu…

No fix yet
Fix from $1,950 2025-11-24
Library System HIGH 8.8
CVE-2025-13580

A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.php. This manipulation of the a…

No fix yet
Fix from $1,950 2025-11-24
Blog Site HIGH 8.8
CVE-2025-13575

A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/…

Mitigation only
Fix from $1,950 2025-11-24