Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Zz CRITICAL 9.8
CVE-2025-1821

A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the fil…

Fix: after 2024-8
Fix from $2,300 2025-03-02
Zz HIGH 8.8
CVE-2025-1820

A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the f…

Fix: after 2024-8
Fix from $1,950 2025-03-02
Zz HIGH 8.8
CVE-2025-1812

A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of the file com/futvan/z/framew…

Fix: 2024-8+
Fix from $1,950 2025-03-02
Unclassified HIGH 7.3
CVE-2025-1811

A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this vulnerability is an unknown …

Mitigation only
Fix from $1,950 2025-03-02
Unclassified HIGH 7.3
CVE-2025-1809

A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projeto…

Mitigation only
Fix from $1,950 2025-03-02
Unclassified HIGH 7.3
CVE-2025-1808

A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?a…

Mitigation only
Fix from $1,950 2025-03-02
Unclassified MEDIUM 6.3
CVE-2025-1797

A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operati…

Mitigation only
Fix from $1,600 2025-03-01
Unclassified MEDIUM 6.5
CVE-2024-13750

The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versi…

Mitigation only
Fix from $1,600 2025-03-01
Loggrove MEDIUM 5.1
CVE-2025-26047

Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.

No fix yet
Fix from $1,600 2025-02-28
Kivicare HIGH 8.8
CVE-2025-1572

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions …

Fix: 3.6.8+
Fix from $1,950 2025-02-28
Gfast CRITICAL 9.8
CVE-2024-55160

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

Fix: after 3.2
Fix from $2,300 2025-02-27
Unclassified CRITICAL 9.8
CVE-2024-13148

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL…

Mitigation only
Fix from $2,300 2025-02-27
Unclassified CRITICAL 9.8
CVE-2025-1751

A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update an…

Mitigation only
Fix from $2,300 2025-02-27
Land Record System MEDIUM 5.5
CVE-2025-25462

A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers t…

No fix yet
Fix from $1,600 2025-02-26
Seacms CRITICAL 9.8
CVE-2025-25516

Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.

Fix: after 13.3
Fix from $2,300 2025-02-25
Seacms CRITICAL 9.8
CVE-2025-25517

Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.

Fix: after 13.3
Fix from $2,300 2025-02-25
Seacms CRITICAL 9.8
CVE-2025-25519

Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.

Fix: after 13.3
Fix from $2,300 2025-02-25
Seacms CRITICAL 9.8
CVE-2025-25520

Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.

Fix: after 13.3
Fix from $2,300 2025-02-25
Seacms CRITICAL 9.8
CVE-2025-25521

Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.

Fix: after 13.3
Fix from $2,300 2025-02-25
Seacms MEDIUM 6.5
CVE-2025-25514

Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.

Fix: after 13.3
Fix from $1,600 2025-02-25
Seacms HIGH 8.8
CVE-2025-25515

Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.

Fix: after 13.3
Fix from $1,950 2025-02-25
Ragflow CRITICAL 9.8
CVE-2025-27135

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL componen…

Fix: after 0.15.1
Fix from $2,300 2025-02-25
Poll Maker CRITICAL 9.8
CVE-2025-26971

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker poll-maker allows Blind SQL …

Fix: 5.6.6+
Fix from $2,300 2025-02-25
Unclassified CRITICAL 9.3
CVE-2025-26974

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-sto…

Mitigation only
Fix from $2,300 2025-02-25
Unclassified CRITICAL 9.3
CVE-2025-26943

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Bl…

Mitigation only
Fix from $2,300 2025-02-25
Unclassified HIGH 7.6
CVE-2025-26946

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider wp-yelp-review-…

Mitigation only
Fix from $1,950 2025-02-25
Unclassified HIGH 8.5
CVE-2025-26915

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Inject…

Mitigation only
Fix from $1,950 2025-02-25
Yawave HIGH 7.5
CVE-2025-1648

The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficie…

Fix: after 2.9.1
Fix from $1,950 2025-02-25
Hikashop HIGH 7.2
CVE-2025-22210

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arb…

Fix: after 5.1.4
Fix from $1,950 2025-02-25
Modernanet CRITICAL 9.8
CVE-2025-1640

A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some unknown functionality of the fi…

Fix: 1.1.1+
Fix from $2,300 2025-02-25