Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.1
CVE-2024-32323

SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information via the if parameter in hcit.p…

Mitigation only
Fix from $1,950 2025-07-17
Fortiweb CRITICAL 9.8
CVE-2025-25257 KEVEPSS 100%

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6…

Fix: 7.0.11 / 7.2.11+
Fix from $2,300 2025-07-17
Wegia HIGH 8.8
CVE-2025-54058

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.4.6+
Fix from $1,950 2025-07-17
Wegia HIGH 8.8
CVE-2025-54060

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.4.6+
Fix from $1,950 2025-07-17
Wegia HIGH 8.8
CVE-2025-54061

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.4.6+
Fix from $1,950 2025-07-17
Wegia HIGH 8.8
CVE-2025-54062

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.4.6+
Fix from $1,950 2025-07-17
Wegia HIGH 8.8
CVE-2025-53946

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.4.5+
Fix from $1,950 2025-07-17
Unclassified HIGH 7.5
CVE-2025-7735

The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary …

Mitigation only
Fix from $1,950 2025-07-17
Wegia CRITICAL 9.8
CVE-2025-53937

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.4.5+
Fix from $2,300 2025-07-16
Unclassified HIGH 7.1
CVE-2025-37104

A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to pe…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.5
CVE-2025-52819

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Envíos pakke allows SQL Injection…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.5
CVE-2025-49876

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profile…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-52714

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows SQL Injecti…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified HIGH 7.6
CVE-2025-49034

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.5
CVE-2025-32574

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection. This issue…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.5
CVE-2025-47645

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edi…

Mitigation only
Fix from $1,950 2025-07-16
Wp Pipes CRITICAL 9.8
CVE-2025-28982

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This i…

Fix: after 1.4.3
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-30936

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod …

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-24759

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugin…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-28959

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener exact-links a…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified HIGH 7.6
CVE-2025-54043

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES smtp-amazon-ses…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.5
CVE-2025-54026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes gymbase_clas…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.6
CVE-2025-48299

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra yayextra allows SQL Inject…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.6
CVE-2025-48301

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP smtp-se…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.6
CVE-2025-48161

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP smtp-sendinblue allows SQL …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.3
CVE-2025-40985

SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data …

Mitigation only
Fix from $1,950 2025-07-16
Opensis HIGH 8.1
CVE-2025-26186

SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php

Patch available
Fix from $1,950 2025-07-15
Unclassified CRITICAL 10.0
CVE-2025-34112

An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances…

Mitigation only
Fix from $2,300 2025-07-15
Wegia HIGH 8.8
CVE-2025-53823

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection…

Fix: 3.4.5+
Fix from $1,950 2025-07-14
Metersphere CRITICAL 9.8
CVE-2025-53639

MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not proper…

Fix: 3.6.5+
Fix from $2,300 2025-07-14