Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.3
CVE-2025-22371

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allow…

Mitigation only
Fix from $2,300 2025-04-14
Unclassified MEDIUM 6.3
CVE-2025-3571

A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnera…

Mitigation only
Fix from $1,600 2025-04-14
Uzy Ssm Mall CRITICAL 9.8
CVE-2025-3559

A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListCont…

No fix yet
Fix from $2,300 2025-04-14
Phpshe CRITICAL 9.8
CVE-2025-3553

A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of the file /admin.php?m…

No fix yet
Fix from $2,300 2025-04-14
Unclassified MEDIUM 6.3
CVE-2025-3534

A vulnerability, which was classified as critical, was found in PowerCreator CMS 1.0. Affected is an unknown function of the file /OpenPublicCourse.a…

Mitigation only
Fix from $1,600 2025-04-13
Unclassified MEDIUM 6.5
CVE-2025-2128

The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter in all versions up to, and i…

Mitigation only
Fix from $1,600 2025-04-11
Unclassified HIGH 8.5
CVE-2025-32681

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log Viewer error-log-viewer-wp al…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.5
CVE-2025-32650

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Accessibility Suite online-accessi…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.5
CVE-2025-32618

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Inject…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified CRITICAL 9.3
CVE-2025-32603

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users Stats wp-online-users-stats …

Mitigation only
Fix from $2,300 2025-04-11
Unclassified HIGH 8.5
CVE-2025-32567

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in dev02ali Easy Post Duplicator easy-post-duplica…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.5
CVE-2025-32558

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ketanajani Duplicate Title Checker duplicate-ti…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified CRITICAL 9.3
CVE-2025-32565

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-desig…

Mitigation only
Fix from $2,300 2025-04-11
Unclassified CRITICAL 9.3
CVE-2025-31565

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-con…

Mitigation only
Fix from $2,300 2025-04-11
Unclassified CRITICAL 9.3
CVE-2025-31599

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows…

Mitigation only
Fix from $2,300 2025-04-11
Unclassified HIGH 8.5
CVE-2025-32687

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce r…

Mitigation only
Fix from $1,950 2025-04-10
Unclassified HIGH 7.6
CVE-2025-32128

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby Locations nearby-locations all…

Mitigation only
Fix from $1,950 2025-04-10
Unclassified HIGH 8.2
CVE-2025-32119

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce card…

Mitigation only
Fix from $1,950 2025-04-10
Unclassified HIGH 7.6
CVE-2025-32685

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aristo Rinjuang WP Inquiries wp-inquiries allow…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.6
CVE-2025-32676

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Picture-Planet GmbH Verowa Connect verowa-conne…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.6
CVE-2025-32677

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solwininfotech WP Social Stream Designer social…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.2
CVE-2025-32550

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin al…

Mitigation only
Fix from $1,950 2025-04-09
Erp HIGH 8.8
CVE-2025-29390

jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.

No fix yet
Fix from $1,950 2025-04-09
Library Manager HIGH 7.2
CVE-2025-29391

horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.

No fix yet
Fix from $1,950 2025-04-09
Flowise HIGH 7.6
CVE-2025-29189

Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.

Fix: after 2.2.3
Fix from $1,950 2025-04-09
Unclassified HIGH 7.3
CVE-2017-20197

A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. Thi…

Patch available
Fix from $1,950 2025-04-09
Joomla\! CRITICAL 9.8
CVE-2025-25226

Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …

Fix: 2.2.0 / 3.4.0+
Fix from $2,300 2025-04-08
Unclassified CRITICAL 9.3
CVE-2025-32020

The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/…

Mitigation only
Fix from $2,300 2025-04-08
Endpoint Manager HIGH 7.2
CVE-2025-22461

SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privile…

Fix: 2022+
Fix from $1,950 2025-04-08
Unclassified MEDIUM 6.5
CVE-2025-3436

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in all …

Mitigation only
Fix from $1,600 2025-04-08