Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Ltl Freight Quotes HIGH 7.5
CVE-2024-13473

The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' param…

Fix: 5.0.21+
Fix from $1,950 2025-02-12
Small Package Quotes HIGH 7.5
CVE-2024-13475

The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and inc…

Fix: 4.5.17+
Fix from $1,950 2025-02-12
Ltl Freight Quotes HIGH 7.5
CVE-2024-13490

The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all v…

Fix: 4.3.8+
Fix from $1,950 2025-02-12
Ebook Downloader HIGH 7.5
CVE-2024-13435

The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due t…

Fix: after 1.0
Fix from $1,950 2025-02-12
Gym Management System CRITICAL 9.8
CVE-2025-1188

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown funct…

No fix yet
Fix from $2,300 2025-02-12
Maxair HIGH 8.8
CVE-2025-1185

A vulnerability was found in pihome-shc PiHome 2.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?Ajax=GetMo…

No fix yet
Fix from $1,950 2025-02-12
Maxair HIGH 8.8
CVE-2025-1184

A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /aja…

No fix yet
Fix from $1,950 2025-02-12
Cacti CRITICAL 9.8
CVE-2025-26520

Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists be…

Fix: 1.2.29+
Fix from $2,300 2025-02-12
Gym Management System CRITICAL 9.8
CVE-2025-1183

A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $2,300 2025-02-12
Unclassified MEDIUM 6.5
CVE-2024-55212

DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.

Mitigation only
Fix from $1,600 2025-02-11
Bookstore Management System HIGH 7.2
CVE-2025-1173

A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the fi…

No fix yet
Fix from $1,950 2025-02-11
Bookstore Management System HIGH 8.8
CVE-2025-1172

A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some un…

No fix yet
Fix from $1,950 2025-02-11
Employee Management System CRITICAL 9.8
CVE-2025-1167

A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknow…

Fix: 192.168.70.3+
Fix from $2,300 2025-02-11
Contact Manager With Export To Vcf CRITICAL 9.8
CVE-2025-1168

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unkn…

No fix yet
Fix from $2,300 2025-02-11
Job Recruitment HIGH 7.5
CVE-2025-1162

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_u…

No fix yet
Fix from $1,950 2025-02-10
Unclassified MEDIUM 6.3
CVE-2025-1158

A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file add…

Mitigation only
Fix from $1,600 2025-02-10
Unclassified HIGH 7.3
CVE-2025-1156

A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unknown code of the file /servlet?…

Mitigation only
Fix from $1,950 2025-02-10
Unclassified MEDIUM 6.3
CVE-2025-1157

A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /mod…

Mitigation only
Fix from $1,600 2025-02-10
Unclassified MEDIUM 5.9
CVE-2024-57178

An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() e…

Mitigation only
Fix from $1,600 2025-02-10
Unclassified MEDIUM 6.3
CVE-2025-1154

A vulnerability, which was classified as critical, has been found in xxyopen Novel up to 3.4.1. Affected by this issue is some unknown functionality …

Mitigation only
Fix from $1,600 2025-02-10
Super Store Finder HIGH 8.2
CVE-2024-13440

The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including,…

Fix: 7.1+
Fix from $1,950 2025-02-09
Unclassified HIGH 7.3
CVE-2025-1117

A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart. This affects an unknown part. The manipulation …

Mitigation only
Fix from $1,950 2025-02-08
Unclassified HIGH 7.3
CVE-2025-1116

A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart. Affected by this iss…

Mitigation only
Fix from $1,950 2025-02-08
Jeecgboot HIGH 7.5
CVE-2024-57606

SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive informati…

No fix yet
Fix from $1,950 2025-02-07
Unclassified HIGH 8.5
CVE-2025-25151

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ulisting allows SQL Injection…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.6
CVE-2025-25116

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sudipto Link to URL / Post link-to-url-post all…

Mitigation only
Fix from $1,950 2025-02-07
Emoncms CRITICAL 9.8
CVE-2025-22992

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper hand…

Fix: after 11.6.9
Fix from $2,300 2025-02-06
Cinema Booking System CRITICAL 9.8
CVE-2024-57430

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queri…

No fix yet
Fix from $2,300 2025-02-06
Responsive E Learning System CRITICAL 9.8
CVE-2020-36084

SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teach…

No fix yet
Fix from $2,300 2025-02-05
Unclassified HIGH 8.5
CVE-2025-22700

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This iss…

Mitigation only
Fix from $1,950 2025-02-04