Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Membership Management System CRITICAL 9.8
CVE-2025-3998

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file r…

No fix yet
Fix from $2,300 2025-04-28
Covid19 Testing Management System CRITICAL 9.8
CVE-2025-3976

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of…

Mitigation only
Fix from $2,300 2025-04-27
Covid19 Testing Management System CRITICAL 9.8
CVE-2025-3973

A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the…

Mitigation only
Fix from $2,300 2025-04-27
Covid19 Testing Management System CRITICAL 9.8
CVE-2025-3974

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown cod…

Mitigation only
Fix from $2,300 2025-04-27
Covid19 Testing Management System CRITICAL 9.8
CVE-2025-3972

A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some…

Mitigation only
Fix from $2,300 2025-04-27
Covid19 Testing Management System CRITICAL 9.8
CVE-2025-3971

A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown fu…

Mitigation only
Fix from $2,300 2025-04-27
News Publishing Site Dashboard HIGH 8.8
CVE-2025-3968

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown co…

No fix yet
Fix from $1,950 2025-04-27
Springboot Admin CRITICAL 9.8
CVE-2025-3957

A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main…

No fix yet
Fix from $2,300 2025-04-27
Novel Cloud CRITICAL 9.8
CVE-2025-3956

A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the function RestResp of the fil…

Mitigation only
Fix from $2,300 2025-04-27
Zxcloud Goldendb HIGH 7.5
CVE-2025-46578

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject com…

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Zxcloud Goldendb HIGH 7.5
CVE-2025-46577

There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Patient Record Management System HIGH 7.5
CVE-2025-3955

A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of th…

No fix yet
Fix from $1,950 2025-04-27
Bus Ticket Booking System CRITICAL 9.8
CVE-2025-25775

Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

No fix yet
Fix from $2,300 2025-04-25
Unclassified MEDIUM 6.5
CVE-2025-28076

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary …

Mitigation only
Fix from $1,600 2025-04-25
Sherpa Orchestrator HIGH 8.8
CVE-2025-46546

In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /…

Mitigation only
Fix from $1,950 2025-04-25
Unclassified MEDIUM 6.5
CVE-2025-29529

ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.as…

Patch available
Fix from $1,600 2025-04-24
Unclassified CRITICAL 9.3
CVE-2025-46248

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-da…

Mitigation only
Fix from $2,300 2025-04-24
Unclassified HIGH 8.5
CVE-2025-39377

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper appsero-helper allows SQL…

Mitigation only
Fix from $1,950 2025-04-24
Online Class And Exam Scheduling System MEDIUM 6.5
CVE-2025-44134

A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of …

No fix yet
Fix from $1,600 2025-04-24
Online Class And Exam Scheduling System MEDIUM 6.5
CVE-2025-44135

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the para…

No fix yet
Fix from $1,600 2025-04-24
Centreon Web HIGH 7.2
CVE-2025-3872

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form …

Fix: 22.10.28 / 23.04.25+
Fix from $1,950 2025-04-24
Unclassified MEDIUM 6.5
CVE-2025-3280

The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_fi…

Mitigation only
Fix from $1,600 2025-04-24
Posthog HIGH 8.0
CVE-2025-1520

PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute…

Fix: 0.3.7+
Fix from $1,950 2025-04-23
Xwiki HIGH 8.8
CVE-2025-32968

XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with S…

Fix: 15.10.16 / 16.4.6+
Fix from $1,950 2025-04-23
Xwiki CRITICAL 9.8
CVE-2025-32969EPSS 78%

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticat…

Fix: 15.10.16 / 16.4.6+
Fix from $2,300 2025-04-23
Unclassified CRITICAL 9.8
CVE-2025-43949

MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statem…

Mitigation only
Fix from $2,300 2025-04-22
Sacco Management System CRITICAL 9.8
CVE-2023-44755

Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.

No fix yet
Fix from $2,300 2025-04-22
Unclassified HIGH 7.2
CVE-2025-3767

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allo…

Mitigation only
Fix from $1,950 2025-04-22
Unclassified HIGH 8.8
CVE-2025-23176

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

No fix yet
Fix from $1,950 2025-04-22
Message Filter For Contact Form 7 HIGH 7.2
CVE-2025-46252

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 c…

Fix: 1.6.3.3+
Fix from $1,950 2025-04-22