Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Freepbx CRITICAL 9.8
CVE-2025-57819 KEVEPSS 88%

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-su…

Fix: 15.0.66 / 16.0.89+
Fix from $2,300 2025-08-28
Online Shopping System Advanced MEDIUM 6.5
CVE-2025-51972

A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supp…

No fix yet
Fix from $1,600 2025-08-28
Online Shopping System Advanced MEDIUM 5.4
CVE-2025-51971

A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user i…

No fix yet
Fix from $1,600 2025-08-28
Online Shopping System Advanced MEDIUM 6.5
CVE-2025-51969

A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the produ…

No fix yet
Fix from $1,600 2025-08-28
Online Shopping System Advanced MEDIUM 6.5
CVE-2025-51968

A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly …

No fix yet
Fix from $1,600 2025-08-28
Unclassified CRITICAL 9.3
CVE-2025-54720

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL …

Mitigation only
Fix from $2,300 2025-08-28
Unclassified HIGH 8.5
CVE-2025-49402

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scriptsbundle Exertio Framework exertio-framewo…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 8.5
CVE-2025-49404

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in purethemes Listeo Core listeo-core allows SQL I…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified CRITICAL 9.3
CVE-2025-39496

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Inje…

Mitigation only
Fix from $2,300 2025-08-28
Unclassified MEDIUM 6.5
CVE-2025-8977

The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and includi…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified CRITICAL 9.3
CVE-2025-34162

An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control Sy…

Mitigation only
Fix from $2,300 2025-08-27
St. Joe Erp System CRITICAL 9.8
CVE-2024-13979

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL …

Mitigation only
Fix from $2,300 2025-08-27
Simple Admin HIGH 7.0
CVE-2025-51667

An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-core system has a limited SQL…

Fix: after 1.6.7
Fix from $1,950 2025-08-27
Nodebb HIGH 8.6
CVE-2025-50979EPSS 8%

NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…

No fix yet
Fix from $1,950 2025-08-27
Diskover MEDIUM 5.3
CVE-2025-50984

diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsa…

No fix yet
Fix from $1,600 2025-08-27
Readarr HIGH 8.3
CVE-2025-50983

SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails …

No fix yet
Fix from $1,950 2025-08-27
Abantecart CRITICAL 9.8
CVE-2025-50972

SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to inde…

Mitigation only
Fix from $2,300 2025-08-27
I Educar HIGH 8.8
CVE-2025-9531

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Ag…

Fix: after 2.10
Fix from $1,950 2025-08-27
I Educar HIGH 8.8
CVE-2025-9532

A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/view. Executing manipulation of…

Fix: after 2.10
Fix from $1,950 2025-08-27
Unclassified MEDIUM 6.9
CVE-2025-30061

In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parameter.

Mitigation only
Fix from $1,600 2025-08-27
Unclassified MEDIUM 6.9
CVE-2025-30059

In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.

Mitigation only
Fix from $1,600 2025-08-27
Unclassified MEDIUM 6.9
CVE-2025-30060

In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" parameter.

Mitigation only
Fix from $1,600 2025-08-27
Unclassified MEDIUM 6.9
CVE-2025-30058

In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.

Mitigation only
Fix from $1,600 2025-08-27
Apartment Management System CRITICAL 9.8
CVE-2025-9511

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /visitor/addvisit…

Mitigation only
Fix from $2,300 2025-08-27
Apartment Management System CRITICAL 9.8
CVE-2025-9508

A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /report/rented_…

Mitigation only
Fix from $2,300 2025-08-27
Apartment Management System CRITICAL 9.8
CVE-2025-9509

A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/f…

Mitigation only
Fix from $2,300 2025-08-27
Apartment Management System CRITICAL 9.8
CVE-2025-9510

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /…

Mitigation only
Fix from $2,300 2025-08-27
Apartment Management System CRITICAL 9.8
CVE-2025-9507

A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/visitor_info.php.…

Mitigation only
Fix from $2,300 2025-08-27
Online Loan Management System CRITICAL 9.8
CVE-2025-9506

A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_plan.…

Mitigation only
Fix from $2,300 2025-08-27
Online Loan Management System CRITICAL 9.8
CVE-2025-9505

A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?acti…

Mitigation only
Fix from $2,300 2025-08-27