Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.3
CVE-2025-47640

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Design…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified HIGH 8.5
CVE-2025-47575

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-47599

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Facturante facturante allows SQL Inj…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified HIGH 8.5
CVE-2025-47478

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profile…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-46539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFable Fable Extra fable-extra allows Blind SQ…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-46460

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Detheme Easy Guide wp-easy-guide allows SQL Inj…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified HIGH 8.5
CVE-2025-46463

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-46455

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IndigoThemes WP HRM LITE wp-hrm-lite-human-reso…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified HIGH 8.7
CVE-2025-41377

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an auth…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-39504

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows B…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-39501

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-31914

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-31056

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCart - Whatsapp Abandoned Cart R…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.3
CVE-2025-31397

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticket Booking with Seat Reservati…

Mitigation only
Fix from $2,300 2025-05-23
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-41407

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.

Fix: 8.5+
Fix from $1,950 2025-05-23
Unclassified HIGH 8.6
CVE-2025-3893

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the …

Mitigation only
Fix from $1,950 2025-05-23
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-36527EPSS 31%

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.

Fix: 8.5+
Fix from $1,950 2025-05-23
Unclassified MEDIUM 5.4
CVE-2025-48701

openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 8.8
CVE-2024-13955

2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials beco…

Mitigation only
Fix from $1,950 2025-05-22
Netmri HIGH 8.8
CVE-2024-52874EPSS 8%

In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.

Fix: 7.6.1+
Fix from $1,950 2025-05-22
Cybercafe Management System CRITICAL 9.8
CVE-2025-5081

A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $2,300 2025-05-22
Online Shopping Portal CRITICAL 9.8
CVE-2025-5079

A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /adm…

No fix yet
Fix from $2,300 2025-05-22
Netmri CRITICAL 9.8
CVE-2025-32814EPSS 41%

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

Fix: 7.6.1+
Fix from $2,300 2025-05-22
Online Shopping Portal CRITICAL 9.8
CVE-2025-5077

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admi…

No fix yet
Fix from $2,300 2025-05-22
Online Shopping Portal CRITICAL 9.8
CVE-2025-5078

A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. …

No fix yet
Fix from $2,300 2025-05-22
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-3836EPSS 5%

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

Fix: 8.5+
Fix from $1,950 2025-05-22
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-41403

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

Fix: 8.5+
Fix from $1,950 2025-05-22
Online Shopping Portal CRITICAL 9.8
CVE-2025-5056

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown fun…

No fix yet
Fix from $2,300 2025-05-21
Online Shopping Portal CRITICAL 9.8
CVE-2025-5057

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $2,300 2025-05-21
Unclassified HIGH 7.0
CVE-2025-3751

The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection attack. This could lead to unauth…

Mitigation only
Fix from $1,950 2025-05-21