Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Advocate Office Management System HIGH 8.8
CVE-2025-2602

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability aff…

No fix yet
Fix from $1,950 2025-03-21
Fastcms MEDIUM 6.3
CVE-2025-2593

A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the f…

Fix: after 0.1.5
Fix from $1,600 2025-03-21
Human Metapneumovirus \(hmpv\) Testing Management System MEDIUM 5.4
CVE-2025-29640

Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter sear…

No fix yet
Fix from $1,600 2025-03-21
Vehicle Record Management System HIGH 7.3
CVE-2025-29641

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.

No fix yet
Fix from $1,950 2025-03-21
Jinher Oa C6 MEDIUM 6.3
CVE-2025-2587

A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. This affects an unknown part of the file IncentivePlanFulfillApppro…

No fix yet
Fix from $1,600 2025-03-21
Unclassified HIGH 8.8
CVE-2025-2585

EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary…

Mitigation only
Fix from $1,950 2025-03-21
Infocad CRITICAL 9.8
CVE-2025-26852

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

Fix: 3.5.2.0+
Fix from $2,300 2025-03-20
Etrakit.net CRITICAL 9.8
CVE-2025-29980

A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can ru…

Patch available
Fix from $2,300 2025-03-20
Anythingllm MEDIUM 5.3
CVE-2024-8251

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embed…

Fix: 1.2.2+
Fix from $1,600 2025-03-20
Unclassified HIGH 7.5
CVE-2024-8055

Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerabi…

Mitigation only
Fix from $1,950 2025-03-20
Unclassified HIGH 8.1
CVE-2024-7764

Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands from user requests. The vulne…

Mitigation only
Fix from $1,950 2025-03-20
Llamaindex HIGH 7.1
CVE-2024-12911

A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection v…

Fix: 0.5.1+
Fix from $1,950 2025-03-20
Llamaindex CRITICAL 9.8
CVE-2024-12909

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql…

Fix: 0.3.0+
Fix from $2,300 2025-03-20
Llamaindex CRITICAL 9.8
CVE-2024-11958

A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version.…

Fix: 0.4.0+
Fix from $2,300 2025-03-20
Db Gpt CRITICAL 9.8
CVE-2024-10835

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control…

No fix yet
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-12016

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection. T…

Mitigation only
Fix from $2,300 2025-03-20
Apache Airflow Providers Mysql MEDIUM 6.3
CVE-2025-27018

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user trigg…

Fix: 6.2.0+
Fix from $1,600 2025-03-19
Drive Server HIGH 7.5
CVE-2024-50631EPSS 25%

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Ser…

Fix: 3.0.4-12699 / 3.2.1-23280+
Fix from $1,950 2025-03-19
Xinhu MEDIUM 6.8
CVE-2024-57151

SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and…

Fix: after 2.6.5
Fix from $1,600 2025-03-18
Glpi CRITICAL 9.8
CVE-2025-24799EPSS 86%

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vul…

Fix: 10.0.18+
Fix from $2,300 2025-03-18
Glpi CRITICAL 9.8
CVE-2025-21619

GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This…

Fix: 10.0.18+
Fix from $2,300 2025-03-18
Yimioa MEDIUM 6.1
CVE-2025-25582

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

Fix: 2024-07-04+
Fix from $1,600 2025-03-18
Yimioa MEDIUM 6.1
CVE-2025-25580

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

Fix: 2024.07.04+
Fix from $1,600 2025-03-18
Yimioa MEDIUM 6.1
CVE-2025-25590

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

Fix: 2024.07.04+
Fix from $1,600 2025-03-18
Evc04 Configuration Interface CRITICAL 9.8
CVE-2024-8997

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL…

Fix: after 18.03.2025
Fix from $2,300 2025-03-18
Boat Booking System HIGH 8.8
CVE-2025-2471

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat…

No fix yet
Fix from $1,950 2025-03-18
Apartment Visitors Management System CRITICAL 9.8
CVE-2025-2472

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this vulnerability is a…

No fix yet
Fix from $2,300 2025-03-18
Company Visitor Management System CRITICAL 9.8
CVE-2025-2473

A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown func…

No fix yet
Fix from $2,300 2025-03-18
Real Estate Property Management System HIGH 7.5
CVE-2025-2419

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of…

No fix yet
Fix from $1,950 2025-03-17
Blood Bank Management System CRITICAL 9.8
CVE-2025-2391

A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the fi…

No fix yet
Fix from $2,300 2025-03-17