Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.3
CVE-2025-49931

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSearch jet-search allows Blind SQ…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.3
CVE-2025-49915

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-a…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.5
CVE-2025-49378

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.5
CVE-2025-48091

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Inje…

Mitigation only
Fix from $1,950 2025-10-22
Daicuo MEDIUM 6.5
CVE-2025-61194

daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.

No fix yet
Fix from $1,600 2025-10-21
Unclassified MEDIUM 6.5
CVE-2025-56450

Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLead…

Mitigation only
Fix from $1,600 2025-10-21
Unclassified HIGH 7.1
CVE-2025-9339

SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injecti…

Mitigation only
Fix from $1,950 2025-10-21
Manageengine Analytics Plus HIGH 8.8
CVE-2025-9428EPSS 26%

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

Fix: 6.1+
Fix from $1,950 2025-10-21
Restaurant Management System Dbms Project MEDIUM 6.5
CVE-2025-60783

There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipul…

No fix yet
Fix from $1,600 2025-10-20
Unclassified HIGH 7.5
CVE-2025-62658

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalyti…

Mitigation only
Fix from $1,950 2025-10-20
Timeprovider 4100 Firmware HIGH 8.8
CVE-2025-47902

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injecti…

Fix: 2.5+
Fix from $1,950 2025-10-20
Unclassified CRITICAL 9.8
CVE-2025-61455

SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorpo…

Mitigation only
Fix from $2,300 2025-10-20
Unclassified CRITICAL 9.3
CVE-2025-41028

A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and d…

Mitigation only
Fix from $2,300 2025-10-20
Vvveb HIGH 7.2
CVE-2025-11944

A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the c…

Fix: after 1.0.7.3
Fix from $1,950 2025-10-19
Unclassified HIGH 7.5
CVE-2025-11691

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() f…

Mitigation only
Fix from $1,950 2025-10-18
Streamax Crocus HIGH 8.8
CVE-2025-11911

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Actio…

No fix yet
Fix from $1,950 2025-10-17
Streamax Crocus HIGH 8.8
CVE-2025-11912

A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query.…

No fix yet
Fix from $1,950 2025-10-17
Streamax Crocus HIGH 8.8
CVE-2025-11910

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /Memory…

No fix yet
Fix from $1,950 2025-10-17
Streamax Crocus HIGH 8.8
CVE-2025-11909

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /Rep…

No fix yet
Fix from $1,950 2025-10-17
Mcms CRITICAL 9.8
CVE-2025-56316

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbit…

Mitigation only
Fix from $2,300 2025-10-17
Unclassified MEDIUM 6.5
CVE-2025-60514

Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.

Patch available
Fix from $1,600 2025-10-17
Dataease HIGH 8.8
CVE-2025-62422

DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface i…

Fix: 2.10.14+
Fix from $1,950 2025-10-17
Chancms HIGH 7.2
CVE-2025-11904

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation …

Fix: after 3.3.2
Fix from $1,950 2025-10-17
Chancms HIGH 7.2
CVE-2025-11903

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a…

Fix: after 3.3.2
Fix from $1,950 2025-10-17
Chancms HIGH 7.2
CVE-2025-11902

A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/f…

Fix: after 3.3.2
Fix from $1,950 2025-10-17
Clipbucket HIGH 7.2
CVE-2025-62423

ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admi…

Fix: 5.5.2-142+
Fix from $1,950 2025-10-16
Unclassified MEDIUM 6.5
CVE-2025-60641

The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel']…

Mitigation only
Fix from $1,600 2025-10-16
Unclassified MEDIUM 5.4
CVE-2025-56699

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to e…

Mitigation only
Fix from $1,600 2025-10-16
Unclassified MEDIUM 5.4
CVE-2025-56700

Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged use…

Mitigation only
Fix from $1,600 2025-10-16
Ultimate Php Board MEDIUM 6.5
CVE-2025-61540

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

Mitigation only
Fix from $1,600 2025-10-16