Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
E Tms CRITICAL 9.8
CVE-2025-59743

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases b…

Mitigation only
Fix from $2,300 2025-10-02
Erpnext MEDIUM 6.5
CVE-2025-56380

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endp…

No fix yet
Fix from $1,600 2025-10-02
Erpnext MEDIUM 6.5
CVE-2025-56381

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orde…

No fix yet
Fix from $1,600 2025-10-02
Unclassified HIGH 8.8
CVE-2025-11020

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of…

Mitigation only
Fix from $1,950 2025-10-02
Django CRITICAL 9.8
CVE-2025-59681

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega…

Fix: 4.2.25 / 5.1.13+
Fix from $2,300 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52040

In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attack…

Patch available
Fix from $1,950 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52041

In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable t…

Patch available
Fix from $1,950 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52042

In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vul…

Patch available
Fix from $1,950 2025-10-01
Erpnext HIGH 8.2
CVE-2025-52039

In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vu…

Patch available
Fix from $1,950 2025-10-01
Unclassified MEDIUM 6.5
CVE-2025-57254

An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execut…

Mitigation only
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52043

In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnera…

Patch available
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52047

In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attac…

Patch available
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52049

In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injectio…

Patch available
Fix from $1,600 2025-09-30
Erpnext MEDIUM 6.5
CVE-2025-52050

In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is v…

Patch available
Fix from $1,600 2025-09-30
Unclassified HIGH 7.5
CVE-2025-8877

The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and incl…

Mitigation only
Fix from $1,950 2025-09-30
Pad Cms HIGH 8.8
CVE-2025-8122

Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…

Fix: after 1.2.1
Fix from $1,950 2025-09-30
Pad Cms HIGH 8.8
CVE-2025-8121

Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…

Fix: after 1.2.1
Fix from $1,950 2025-09-30
Unclassified CRITICAL 9.8
CVE-2024-13150

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.…

No fix yet
Fix from $2,300 2025-09-29
Automate HIGH 8.8
CVE-2025-8868EPSS 23%

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict…

Fix: 4.13.295+
Fix from $1,950 2025-09-29
Automate HIGH 8.8
CVE-2025-6724

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict…

Fix: 4.13.295+
Fix from $1,950 2025-09-29
Student Grading System CRITICAL 9.8
CVE-2025-11118

A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such …

Mitigation only
Fix from $2,300 2025-09-28
Simple Scheduling System CRITICAL 9.8
CVE-2025-11116

A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of …

Mitigation only
Fix from $2,300 2025-09-28
Simple Scheduling System CRITICAL 9.8
CVE-2025-11115

A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown functionality of the file /addti…

Mitigation only
Fix from $2,300 2025-09-28
Online Leave Application HIGH 8.8
CVE-2025-11113

A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulat…

No fix yet
Fix from $1,950 2025-09-28
Online Leave Application HIGH 8.8
CVE-2025-11114

A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicat…

No fix yet
Fix from $1,950 2025-09-28
Advanced Online Voting System CRITICAL 9.8
CVE-2025-11111

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/candida…

Mitigation only
Fix from $2,300 2025-09-28
Online Learning Management System CRITICAL 9.8
CVE-2025-11110

A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admi…

Mitigation only
Fix from $2,300 2025-09-28
Computer Sales And Inventory System CRITICAL 9.8
CVE-2025-11109

A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/u…

Mitigation only
Fix from $2,300 2025-09-28
Simple Scheduling System CRITICAL 9.8
CVE-2025-11108

A vulnerability was determined in code-projects Simple Scheduling System 1.0. Impacted is an unknown function of the file /schedulingsystem/addroom.p…

Mitigation only
Fix from $2,300 2025-09-28
Simple Scheduling System CRITICAL 9.8
CVE-2025-11107

A vulnerability was found in code-projects Simple Scheduling System 1.0. This issue affects some unknown processing of the file /schedulingsystem/add…

Mitigation only
Fix from $2,300 2025-09-28