Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Svx Portal MEDIUM 6.0
CVE-2025-63724

SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.

No fix yet
Fix from $1,600 2025-11-14
Zzcms HIGH 8.8
CVE-2025-13171

A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument…

No fix yet
Fix from $1,950 2025-11-14
Gym Management System HIGH 8.8
CVE-2025-13172

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php…

Mitigation only
Fix from $1,950 2025-11-14
Simple Online Hotel Reservation System CRITICAL 9.8
CVE-2025-13169

A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of th…

Mitigation only
Fix from $2,300 2025-11-14
Simple Online Hotel Reservation System CRITICAL 9.8
CVE-2025-13170

A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /adm…

Mitigation only
Fix from $2,300 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-44636

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.

Mitigation only
Fix from $1,600 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-44639

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.

No fix yet
Fix from $1,600 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-44640

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.

No fix yet
Fix from $1,600 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-55016

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

No fix yet
Fix from $1,600 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-44630

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lna…

No fix yet
Fix from $1,600 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-44632

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

No fix yet
Fix from $1,600 2025-11-14
Student Record System MEDIUM 6.5
CVE-2024-44633

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.

No fix yet
Fix from $1,600 2025-11-14
Ury CRITICAL 9.8
CVE-2025-13168

A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py.…

Fix: 0.2.1+
Fix from $2,300 2025-11-14
Unclassified HIGH 8.7
CVE-2022-4984

ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerabi…

Mitigation only
Fix from $1,950 2025-11-13
Hibos CRITICAL 9.8
CVE-2025-13123

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdat…

Mitigation only
Fix from $2,300 2025-11-13
Patients Waiting Area Queue Management System CRITICAL 9.8
CVE-2025-13122

A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppo…

Mitigation only
Fix from $2,300 2025-11-13
Unclassified HIGH 7.3
CVE-2025-13121

A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/Sto…

Mitigation only
Fix from $1,950 2025-11-13
Responsive Hotel Site CRITICAL 9.8
CVE-2025-13075

A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Perfo…

Mitigation only
Fix from $2,300 2025-11-12
Responsive Hotel Site CRITICAL 9.8
CVE-2025-13076

A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Exe…

Mitigation only
Fix from $2,300 2025-11-12
Alumni Management System CRITICAL 9.8
CVE-2025-13059

A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career…

Mitigation only
Fix from $2,300 2025-11-12
Survey Application System CRITICAL 9.8
CVE-2025-13060

A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey…

Mitigation only
Fix from $2,300 2025-11-12
Harmony CRITICAL 9.8
CVE-2025-56385

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-suppl…

Mitigation only
Fix from $2,300 2025-11-12
School Fees Payment Management System CRITICAL 9.8
CVE-2025-13057

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=s…

Mitigation only
Fix from $2,300 2025-11-12
Unclassified HIGH 7.6
CVE-2025-64293

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Analytics 0-day-analytics allows …

Mitigation only
Fix from $1,950 2025-11-12
Community Development CRITICAL 9.8
CVE-2025-64280

A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.

Mitigation only
Fix from $2,300 2025-11-12
Unclassified MEDIUM 6.5
CVE-2025-11454

The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_s…

Mitigation only
Fix from $1,600 2025-11-12
Sql Server 2016 HIGH 8.8
CVE-2025-59499

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6475.1 / 13.0.7070.1+
Fix from $1,950 2025-11-11
Unclassified CRITICAL 9.8
CVE-2025-8324

Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.

Mitigation only
Fix from $2,300 2025-11-11
Unclassified MEDIUM 5.4
CVE-2025-42889

SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this …

Mitigation only
Fix from $1,600 2025-11-11
Torrentpier HIGH 8.8
CVE-2025-64519

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL i…

Fix: after 2.8.8
Fix from $1,950 2025-11-10