Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Restaurant Website Restoran MEDIUM 6.5
CVE-2025-63878

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

No fix yet
Fix from $1,600 2025-11-19
I Educar HIGH 7.2
CVE-2025-65022

i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exis…

Fix: after 2.10.0
Fix from $1,950 2025-11-19
I Educar HIGH 7.2
CVE-2025-65023

i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exis…

Fix: after 2.10.0
Fix from $1,950 2025-11-19
I Educar HIGH 7.2
CVE-2025-65024

i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exis…

Fix: after 2.10.0
Fix from $1,950 2025-11-19
Courier Management System CRITICAL 9.8
CVE-2025-13396

A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This man…

Mitigation only
Fix from $2,300 2025-11-19
Unclassified CRITICAL 9.8
CVE-2025-10437

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer In…

Mitigation only
Fix from $2,300 2025-11-19
Unclassified HIGH 7.3
CVE-2025-13395

A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted element is the function Login o…

Mitigation only
Fix from $1,950 2025-11-19
Unclassified HIGH 7.5
CVE-2025-12646

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 du…

Mitigation only
Fix from $1,950 2025-11-19
Librenms MEDIUM 5.5
CVE-2025-65093

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerabi…

Fix: 25.11.0+
Fix from $1,600 2025-11-18
Dzzoffice CRITICAL 9.8
CVE-2025-63694

DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

Fix: after 2.3.7
Fix from $2,300 2025-11-18
Hospital Management System MEDIUM 6.5
CVE-2025-63512

kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The applicat…

No fix yet
Fix from $1,600 2025-11-18
Fortivoice HIGH 8.8
CVE-2025-58692

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7…

Fix: 7.0.8 / 7.2.3+
Fix from $1,950 2025-11-18
Unclassified MEDIUM 5.3
CVE-2025-9977

Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an…

Mitigation only
Fix from $1,600 2025-11-18
Train Station Ticketing System HIGH 8.8
CVE-2025-13347

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save…

No fix yet
Fix from $1,950 2025-11-18
Train Station Ticketing System HIGH 8.8
CVE-2025-13346

A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_sta…

No fix yet
Fix from $1,950 2025-11-18
Train Station Ticketing System CRITICAL 9.8
CVE-2025-13344

A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of th…

Mitigation only
Fix from $2,300 2025-11-18
Train Station Ticketing System HIGH 8.8
CVE-2025-13345

A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality…

No fix yet
Fix from $1,950 2025-11-18
Winplus CRITICAL 9.8
CVE-2025-41348

SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete dat…

Mitigation only
Fix from $2,300 2025-11-18
Unclassified HIGH 7.1
CVE-2025-12411

The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' parameter in versions up to, and inc…

No fix yet
Fix from $1,950 2025-11-18
Simple Pizza Ordering System CRITICAL 9.8
CVE-2025-13323

A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Pe…

Mitigation only
Fix from $2,300 2025-11-18
Student Information System HIGH 8.8
CVE-2025-13325

A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_ed…

No fix yet
Fix from $1,950 2025-11-18
Courier Management System CRITICAL 9.8
CVE-2025-13302

A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such ma…

Mitigation only
Fix from $2,300 2025-11-17
Courier Management System CRITICAL 9.8
CVE-2025-13303

A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /sear…

Mitigation only
Fix from $2,300 2025-11-17
Web Based Internet Laboratory Management System CRITICAL 9.8
CVE-2025-13300

A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /sett…

Mitigation only
Fix from $2,300 2025-11-17
Web Based Internet Laboratory Management System CRITICAL 9.8
CVE-2025-13301

A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functiona…

Mitigation only
Fix from $2,300 2025-11-17
Web Based Internet Laboratory Management System CRITICAL 9.8
CVE-2025-13298

A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrol…

Mitigation only
Fix from $2,300 2025-11-17
Web Based Internet Laboratory Management System CRITICAL 9.8
CVE-2025-13299

A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/control…

Mitigation only
Fix from $2,300 2025-11-17
Online Shopping Portal CRITICAL 9.8
CVE-2024-44659

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

Mitigation only
Fix from $2,300 2025-11-17
Online Shopping Portal MEDIUM 6.5
CVE-2024-44664

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-d…

No fix yet
Fix from $1,600 2025-11-17
Online Shopping Portal MEDIUM 6.5
CVE-2024-44660

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.

No fix yet
Fix from $1,600 2025-11-17