Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Yifang HIGH 8.8
CVE-2025-9399

A vulnerability was detected in YiFang CMS up to 2.0.5. Affected by this issue is some unknown functionality of the file app/logic/L_tool.php. The ma…

Fix: after 2.0.5
Fix from $1,950 2025-08-25
Zhiyou Erp CRITICAL 9.8
CVE-2025-9391

A weakness has been identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this issue is the function getFieldValue of the component com.artery.work…

Fix: after 11.0
Fix from $2,300 2025-08-24
Centreon Web HIGH 8.8
CVE-2025-6791

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralizati…

Fix: 23.10.26 / 24.04.16+
Fix from $1,950 2025-08-22
Login Signup CRITICAL 9.8
CVE-2025-51092

The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions l…

Mitigation only
Fix from $2,300 2025-08-22
Streampark HIGH 7.6
CVE-2024-48988

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade t…

Fix: 2.1.6+
Fix from $1,950 2025-08-22
Centreon Web HIGH 7.2
CVE-2025-4650

User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements…

Fix: 23.10.26 / 24.04.16+
Fix from $1,950 2025-08-22
Yoosee HIGH 8.8
CVE-2025-52085

An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend AP…

No fix yet
Fix from $1,950 2025-08-22
Jeewms CRITICAL 9.8
CVE-2024-53499

Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

Mitigation only
Fix from $2,300 2025-08-22
Jeecgboot MEDIUM 6.5
CVE-2025-51825

JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoi…

Fix: after 3.8.0
Fix from $1,600 2025-08-22
Webitr HIGH 7.5
CVE-2025-9255

WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read data…

Fix: 2_1_0_33+
Fix from $1,950 2025-08-22
Apartment Management System CRITICAL 9.8
CVE-2025-9311

A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fai…

Mitigation only
Fix from $2,300 2025-08-21
Wegia HIGH 8.8
CVE-2025-57761

WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html/funcionario/dependente_remov…

Fix: 3.4.10+
Fix from $1,950 2025-08-21
Online Course Registration CRITICAL 9.8
CVE-2025-9307

A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulatio…

Mitigation only
Fix from $2,300 2025-08-21
Online Bank Management System CRITICAL 9.8
CVE-2025-9304

A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of the file /bank/show.php. Execu…

Mitigation only
Fix from $2,300 2025-08-21
Online Bank Management System CRITICAL 9.8
CVE-2025-9305

A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the fi…

Mitigation only
Fix from $2,300 2025-08-21
Easy Hosting Control Panel MEDIUM 5.4
CVE-2025-50860

SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate datab…

No fix yet
Fix from $1,600 2025-08-21
User Management System CRITICAL 9.8
CVE-2025-9302

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipu…

Mitigation only
Fix from $2,300 2025-08-21
I Educar HIGH 8.8
CVE-2025-9236

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php …

Fix: after 2.10
Fix from $1,950 2025-08-20
Unclassified HIGH 7.3
CVE-2025-9238

A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affected is an unknown function o…

Mitigation only
Fix from $1,950 2025-08-20
Online Artwork And Fine Arts Project CRITICAL 9.8
CVE-2025-55444

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote at…

Mitigation only
Fix from $2,300 2025-08-20
Frappe HIGH 7.5
CVE-2025-55732

Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted …

Fix: 14.96.15 / 15.74.2+
Fix from $1,950 2025-08-20
Frappe HIGH 8.8
CVE-2025-55731

Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via…

Fix: 14.96.15 / 15.74.2+
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.3
CVE-2025-54726

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-li…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.3
CVE-2025-54048

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp …

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 8.5
CVE-2025-49891

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in uxper Uxper Booking uxper-booking allows Blind …

Mitigation only
Fix from $1,950 2025-08-20
Sports Management System CRITICAL 9.8
CVE-2025-9156

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Pe…

Mitigation only
Fix from $2,300 2025-08-19
Online Tour \& Travel Management System CRITICAL 9.8
CVE-2025-9155

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget…

Mitigation only
Fix from $2,300 2025-08-19
Easy Hosting Control Panel MEDIUM 6.5
CVE-2025-50926

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Address…

No fix yet
Fix from $1,600 2025-08-19
Online Tour \& Travel Management System CRITICAL 9.8
CVE-2025-9154

A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page…

Mitigation only
Fix from $2,300 2025-08-19
Unclassified HIGH 7.3
CVE-2025-9150

A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of…

Mitigation only
Fix from $1,950 2025-08-19