Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Sql Server 2016 HIGH 8.8
CVE-2025-53727

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6465.1 / 13.0.7060.1+
Fix from $1,950 2025-08-12
Sql Server 2016 HIGH 8.8
CVE-2025-49759

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6465.1 / 13.0.7060.1+
Fix from $1,950 2025-08-12
Sql Server 2022 HIGH 8.8
CVE-2025-47954

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 16.0.1145.1 / 16.0.4210.1+
Fix from $1,950 2025-08-12
Wegia CRITICAL 9.8
CVE-2025-55167

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vuln…

Fix: 3.4.8+
Fix from $2,300 2025-08-12
Avalanche HIGH 7.2
CVE-2025-8296

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL que…

Fix: 6.4.8.8008+
Fix from $1,950 2025-08-12
Unclassified HIGH 7.8
CVE-2025-55156

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_…

Patch available
Fix from $1,950 2025-08-11
Unclassified CRITICAL 9.8
CVE-2024-32640EPSS 70%

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injec…

Patch available
Fix from $2,300 2025-08-11
Simple Art Gallery CRITICAL 9.8
CVE-2025-8811

A vulnerability, which was classified as critical, has been found in code-projects Simple Art Gallery 1.0. Affected by this issue is some unknown fun…

Mitigation only
Fix from $2,300 2025-08-10
Online Medicine Guide CRITICAL 9.8
CVE-2025-8809

A vulnerability classified as critical has been found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /addeli…

Mitigation only
Fix from $2,300 2025-08-10
Adp Application Developer Platform CRITICAL 9.8
CVE-2025-8806

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been classified as crit…

Mitigation only
Fix from $2,300 2025-08-10
Monitoring Platform CRITICAL 9.8
CVE-2025-8773

A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown functi…

Mitigation only
Fix from $2,300 2025-08-09
Unclassified HIGH 7.3
CVE-2025-8744

A vulnerability classified as critical was found in CesiumLab Web up to 4.0. This vulnerability affects unknown code of the file /lodmodels/. The man…

Mitigation only
Fix from $1,950 2025-08-09
Unclassified CRITICAL 10.0
CVE-2012-10047

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth…

Mitigation only
Fix from $2,300 2025-08-08
Micollab HIGH 8.8
CVE-2025-52914

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacke…

Fix: 9.8.3.103 / 10.1.0.10+
Fix from $1,950 2025-08-08
Openmetadata MEDIUM 6.5
CVE-2025-50467

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio…

Fix: after 1.4.4
Fix from $1,600 2025-08-08
Openmetadata MEDIUM 6.5
CVE-2025-50468

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO i…

Fix: after 1.4.4
Fix from $1,600 2025-08-08
Openmetadata HIGH 8.8
CVE-2025-50465

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio…

Fix: after 1.4.4
Fix from $1,950 2025-08-08
Openmetadata MEDIUM 6.5
CVE-2025-50466

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio…

Fix: after 1.4.4
Fix from $1,600 2025-08-08
Woes Intelligent Optimization Energy Saving System HIGH 8.8
CVE-2025-8706

A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnera…

No fix yet
Fix from $1,950 2025-08-08
Woes Intelligent Optimization Energy Saving System HIGH 8.8
CVE-2025-8703

A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknow…

No fix yet
Fix from $1,950 2025-08-08
Woes Intelligent Optimization Energy Saving System HIGH 8.8
CVE-2025-8704

A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affec…

No fix yet
Fix from $1,950 2025-08-08
Woes Intelligent Optimization Energy Saving System HIGH 8.8
CVE-2025-8705

A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknow…

No fix yet
Fix from $1,950 2025-08-08
Woes Intelligent Optimization Energy Saving System HIGH 8.8
CVE-2025-8702

A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part…

No fix yet
Fix from $1,950 2025-08-08
Woes Intelligent Optimization Energy Saving System HIGH 8.8
CVE-2025-8701

A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is…

No fix yet
Fix from $1,950 2025-08-07
Hospital Management System CRITICAL 9.8
CVE-2023-41525

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

Mitigation only
Fix from $2,300 2025-08-07
Hospital Management System CRITICAL 9.8
CVE-2023-41526

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameter…

Mitigation only
Fix from $2,300 2025-08-07
Hospital Management System CRITICAL 9.8
CVE-2023-41527

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

Mitigation only
Fix from $2,300 2025-08-07
Hospital Management System CRITICAL 9.8
CVE-2023-41528

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail …

Mitigation only
Fix from $2,300 2025-08-07
Hospital Management System CRITICAL 9.8
CVE-2023-41530

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

Mitigation only
Fix from $2,300 2025-08-07
Hospital Management System HIGH 8.8
CVE-2023-41531

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameter…

Mitigation only
Fix from $1,950 2025-08-07