Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Novel Plus CRITICAL 9.8
CVE-2025-3856

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/s…

No fix yet
Fix from $2,300 2025-04-22
Webserver CRITICAL 9.8
CVE-2025-3847

A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httpreq…

Mitigation only
Fix from $2,300 2025-04-21
Webserver CRITICAL 9.8
CVE-2025-3846

A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of…

Mitigation only
Fix from $2,300 2025-04-21
Managewiki HIGH 8.0
CVE-2025-32956

ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a n…

Fix: 2025-04-20+
Fix from $1,950 2025-04-21
Men Salon Management System CRITICAL 9.8
CVE-2025-3828

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the…

No fix yet
Fix from $2,300 2025-04-20
Men Salon Management System CRITICAL 9.8
CVE-2025-3829

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the f…

No fix yet
Fix from $2,300 2025-04-20
Men Salon Management System CRITICAL 9.8
CVE-2025-3827

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of t…

No fix yet
Fix from $2,300 2025-04-20
Unclassified MEDIUM 6.3
CVE-2025-3818

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the f…

Mitigation only
Fix from $1,600 2025-04-19
Men Salon Management System CRITICAL 9.8
CVE-2025-3819

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown…

No fix yet
Fix from $2,300 2025-04-19
Online Eyewear Shop HIGH 8.8
CVE-2025-3817

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processi…

No fix yet
Fix from $1,950 2025-04-19
Wcms CRITICAL 9.8
CVE-2025-3800

A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/cont…

No fix yet
Fix from $2,300 2025-04-19
Wcms CRITICAL 9.8
CVE-2025-3799

A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousControl…

No fix yet
Fix from $2,300 2025-04-19
Seacms HIGH 7.2
CVE-2025-3797

A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=de…

Fix: after 13.3
Fix from $1,950 2025-04-19
Unclassified HIGH 7.5
CVE-2025-2010

The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resu…

Mitigation only
Fix from $1,950 2025-04-19
Men Salon Management System HIGH 8.8
CVE-2025-3796

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/…

No fix yet
Fix from $1,950 2025-04-18
Nameless MEDIUM 6.5
CVE-2025-32389

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injectio…

Fix: 2.1.4+
Fix from $1,600 2025-04-18
Seacms HIGH 7.2
CVE-2025-3792

A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin…

Fix: after 13.3
Fix from $1,950 2025-04-18
Unclassified CRITICAL 9.3
CVE-2025-39471

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal Survey modal-survey.This issue…

Mitigation only
Fix from $2,300 2025-04-18
Dietiqa CRITICAL 9.8
CVE-2025-28009

A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.

Mitigation only
Fix from $2,300 2025-04-17
Foxcms HIGH 7.2
CVE-2025-29181

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

Fix: after 1.25
Fix from $1,950 2025-04-17
Foxcms HIGH 7.2
CVE-2025-29180

In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters…

Fix: after 1.25
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.3
CVE-2025-39595

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows SQL …

Mitigation only
Fix from $2,300 2025-04-17
Unclassified HIGH 8.5
CVE-2025-39569

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows Blin…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified HIGH 8.5
CVE-2025-39586

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profile…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.3
CVE-2025-39587

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calculator Builder cost-calculato…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.3
CVE-2025-32665

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator office-locator all…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.3
CVE-2025-32636

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic local-magic allows SQL…

Mitigation only
Fix from $2,300 2025-04-17
Js Job Manager CRITICAL 9.8
CVE-2025-32626

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Manager js-jobs allows SQL Injec…

Fix: after 2.0.2
Fix from $2,300 2025-04-17
Unclassified HIGH 8.5
CVE-2025-32573

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. Th…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.3
CVE-2025-27302

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Marrero CHATLIVE chatlive allows…

Mitigation only
Fix from $2,300 2025-04-17