Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Wpschoolpress MEDIUM 6.5
CVE-2025-1670

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and i…

Fix: after 2.2.16
Fix from $1,600 2025-03-15
Unclassified HIGH 8.7
CVE-2024-54445

Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the at…

Mitigation only
Fix from $1,950 2025-03-14
Unclassified HIGH 7.1
CVE-2024-54446

Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi techniq…

Mitigation only
Fix from $1,950 2025-03-14
Unclassified HIGH 7.1
CVE-2024-54447

Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique t…

Mitigation only
Fix from $1,950 2025-03-14
Unclassified HIGH 8.7
CVE-2024-12245

Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the a…

Mitigation only
Fix from $1,950 2025-03-14
Fortiweb HIGH 7.2
CVE-2022-29059

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6…

Fix: 7.0.2+
Fix from $1,950 2025-03-14
Analyticswp CRITICAL 9.8
CVE-2024-13321

The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to, and including, 2.0.0 due to…

Fix: 2.1.0+
Fix from $2,300 2025-03-14
Wpcom Member HIGH 7.5
CVE-2025-2221

The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, …

Fix: 1.7.7+
Fix from $1,950 2025-03-14
Auto Atendimento MEDIUM 6.8
CVE-2025-30022

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.

No fix yet
Fix from $1,600 2025-03-14
Auto Atendimento CRITICAL 9.8
CVE-2025-26163

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.

No fix yet
Fix from $2,300 2025-03-14
User Registration \& Login And User Management System MEDIUM 6.1
CVE-2025-28011

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote at…

No fix yet
Fix from $1,600 2025-03-13
Dataease MEDIUM 6.5
CVE-2025-24974

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize a…

Fix: 2.10.6+
Fix from $1,600 2025-03-13
Dataease MEDIUM 6.5
CVE-2025-27103

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allo…

Fix: 2.10.6+
Fix from $1,600 2025-03-13
Unclassified HIGH 7.5
CVE-2025-2106

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all ve…

Mitigation only
Fix from $1,950 2025-03-13
Unclassified HIGH 7.5
CVE-2025-2107

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResultAndDie() function in all ver…

Mitigation only
Fix from $1,950 2025-03-13
Unclassified CRITICAL 10.0
CVE-2025-22954EPSS 26%

GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid …

Mitigation only
Fix from $2,300 2025-03-12
Warehouse Refinement Management System CRITICAL 9.8
CVE-2025-2217

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessR…

No fix yet
Fix from $2,300 2025-03-12
Abo.cms MEDIUM 6.5
CVE-2021-37787

The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request…

Fix: after 5.9.3
Fix from $1,600 2025-03-11
Pimcore HIGH 8.8
CVE-2025-27617

Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cau…

Fix: 11.5.4+
Fix from $1,950 2025-03-11
Fortisandbox HIGH 8.8
CVE-2024-54026

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.…

Fix: 4.4.7+
Fix from $1,950 2025-03-11
Fortianalyzer MEDIUM 6.7
CVE-2024-33501

Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2025-03-11
Unclassified MEDIUM 5.3
CVE-2025-22370

Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL co…

Mitigation only
Fix from $1,600 2025-03-11
Ftcms HIGH 7.2
CVE-2025-2132

A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists o…

No fix yet
Fix from $1,950 2025-03-09
Jux Real Estate HIGH 8.8
CVE-2025-2126EPSS 11%

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the f…

Mitigation only
Fix from $1,950 2025-03-09
Unclassified HIGH 7.3
CVE-2025-2118

A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown part of the file /admin/login…

Mitigation only
Fix from $1,950 2025-03-09
Unclassified MEDIUM 6.3
CVE-2025-2117

A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affe…

Mitigation only
Fix from $1,600 2025-03-09
Atsvd CRITICAL 9.8
CVE-2025-2113

A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this issue is some unknown functiona…

Fix: after 3.4.1
Fix from $2,300 2025-03-09
Yaoqishan CRITICAL 9.8
CVE-2025-2112

A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declared as critical. Affected by t…

Fix: 2020-02-29+
Fix from $2,300 2025-03-08
Wp Recall CRITICAL 9.8
CVE-2025-1323

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versio…

Fix: 16.26.12+
Fix from $2,300 2025-03-08
Pre School Enrollment System CRITICAL 9.8
CVE-2025-2088

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affected is an unknown function of…

No fix yet
Fix from $2,300 2025-03-07