Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.8
CVE-2025-10968

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft S…

Mitigation only
Fix from $1,950 2025-11-07
Best House Rental Management System CRITICAL 9.8
CVE-2025-12853

A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_c…

Mitigation only
Fix from $2,300 2025-11-07
Unclassified CRITICAL 9.3
CVE-2025-10870

SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete databases by sending POST and GET …

Mitigation only
Fix from $2,300 2025-11-07
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34247

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authent…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34241

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authe…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34242

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authentica…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34243

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34244

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows …

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34245

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows …

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34246

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an auth…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34240

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an au…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Iview HIGH 7.2
CVE-2022-50595

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $1,950 2025-11-06
Iview CRITICAL 9.8
CVE-2022-50591

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $2,300 2025-11-06
Iview HIGH 7.2
CVE-2022-50592

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $1,950 2025-11-06
Iview CRITICAL 9.8
CVE-2022-50593

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $2,300 2025-11-06
Iview HIGH 7.5
CVE-2022-50594

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa…

Fix: 5.7.04.6425+
Fix from $1,950 2025-11-06
Suitecrm CRITICAL 9.8
CVE-2022-50589

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionalit…

Fix: 7.12.6+
Fix from $2,300 2025-11-06
Unclassified HIGH 8.5
CVE-2025-60239

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codexpert, Inc CoSchool LMS coschool allows Bli…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.3
CVE-2025-52773

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Payment Gateway Plugin hcv4-payme…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.3
CVE-2025-48089

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Education WordPress Theme | HiSt…

Mitigation only
Fix from $2,300 2025-11-06
Smartseo HIGH 8.5
CVE-2025-28953

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injec…

Mitigation only
Fix from $1,950 2025-11-06
Clipbucket MEDIUM 6.5
CVE-2025-64114

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrators with plugin management pri…

Fix: 5.5.2-152+
Fix from $1,600 2025-11-06
Open Source Social Network MEDIUM 6.5
CVE-2025-63585

OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.

Mitigation only
Fix from $1,600 2025-11-05
Quipux CRITICAL 9.9
CVE-2025-55343

Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.p…

Mitigation only
Fix from $2,300 2025-11-05
Django CRITICAL 9.1
CVE-2025-64459EPSS 19%

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `Qu…

Fix: 4.2.26 / 5.1.14+
Fix from $2,300 2025-11-05
Unclassified HIGH 7.5
CVE-2025-12197EPSS 17%

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insuffi…

Mitigation only
Fix from $1,950 2025-11-05
Unclassified HIGH 7.5
CVE-2025-32786EPSS 7%

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below ar…

Mitigation only
Fix from $1,950 2025-11-04
Unclassified CRITICAL 9.8
CVE-2025-12463

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/P…

Mitigation only
Fix from $2,300 2025-11-03
Car Booking System Php CRITICAL 9.8
CVE-2025-63451

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.

Mitigation only
Fix from $2,300 2025-11-03
Car Booking System Php CRITICAL 9.4
CVE-2025-63452

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.

No fix yet
Fix from $2,300 2025-11-03