Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.3
CVE-2025-41019

SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' p…

Mitigation only
Fix from $2,300 2025-10-16
Exito CRITICAL 9.8
CVE-2025-41018

SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' pa…

Mitigation only
Fix from $2,300 2025-10-16
Unclassified HIGH 7.5
CVE-2025-11177

The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, and including, 1.11.2 due to in…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified MEDIUM 6.5
CVE-2025-11365

The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versio…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified MEDIUM 6.5
CVE-2025-10660

The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.0.3 due to i…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified MEDIUM 6.5
CVE-2025-10682

The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to insufficient neutralization o…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified MEDIUM 6.5
CVE-2025-10730

The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all versions up to, and including, 4…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 7.5
CVE-2025-10743

The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and including, 1.3.2 due to insufficient…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified MEDIUM 6.5
CVE-2025-10575

The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter handled by the WPJqueryPaged::get…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 7.5
CVE-2025-11501

The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all versions up to, and including,…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified HIGH 8.6
CVE-2025-61675EPSS 39%

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions pr…

Mitigation only
Fix from $1,950 2025-10-14
Online Examination System CRITICAL 9.8
CVE-2025-11736

A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Thi…

Mitigation only
Fix from $2,300 2025-10-14
Configuration Manager 2403 HIGH 8.8
CVE-2025-59213

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attack…

Fix: 5.00.9128.1035 / 5.00.9132.1029+
Fix from $1,950 2025-10-14
Configuration Manager 2403 MEDIUM 6.8
CVE-2025-55320

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker…

Fix: 5.00.9128.1035 / 5.00.9132.1029+
Fix from $1,600 2025-10-14
Unclassified CRITICAL 9.8
CVE-2025-10610

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry …

Mitigation only
Fix from $2,300 2025-10-14
Sinec Nms HIGH 8.8
CVE-2025-40755

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAnd…

Fix: 4.0+
Fix from $1,950 2025-10-14
Endpoint Manager MEDIUM 6.5
CVE-2025-62388

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62389

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62390

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62391

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62392

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62383

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62384

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62385

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62386

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-62387

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Wegia HIGH 8.8
CVE-2025-62360

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was iden…

Fix: 3.5.1+
Fix from $1,950 2025-10-13
Endpoint Manager MEDIUM 6.5
CVE-2025-11623

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2025-10-13
Wegia HIGH 8.8
CVE-2025-62177

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was ide…

Fix: 3.5.1+
Fix from $1,950 2025-10-13
Wegia HIGH 8.8
CVE-2025-62179

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was ide…

Fix: 3.5.1+
Fix from $1,950 2025-10-13