Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified CRITICAL 9.3
CVE-2025-24664

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – Worldwid…

Mitigation only
Fix from $2,300 2025-01-27
Altra Side Menu HIGH 7.2
CVE-2024-12773

The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perf…

Fix: after 2.0
Fix from $1,950 2025-01-27
Unclassified MEDIUM 6.3
CVE-2017-20196

A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the fi…

No fix yet
Fix from $1,600 2025-01-26
Quiz Maker HIGH 7.5
CVE-2024-10628

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and…

Fix: 8.8.0.100 / 21.8.0.100+
Fix from $1,950 2025-01-26
Maximo Application Suite HIGH 8.8
CVE-2024-35148

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially craf…

Mitigation only
Fix from $1,950 2025-01-25
Go Cms MEDIUM 6.8
CVE-2024-57095

SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.

No fix yet
Fix from $1,600 2025-01-24
Unclassified HIGH 8.5
CVE-2025-24728

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre Bug Library bug-library allows…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 7.6
CVE-2025-24683

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill RSVP and Event Management rsvp allows …

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 7.6
CVE-2025-24659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-p…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 7.6
CVE-2025-24663

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mra13 Simple Download Monitor simple-download-m…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 8.5
CVE-2025-24669

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serpednet SERPed.net serped-net allows SQL Inje…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 8.5
CVE-2025-24672

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople Form Builder CP cp-easy-form-builder…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 7.6
CVE-2025-24587EPSS 36%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscription Popup email-subscribe al…

Mitigation only
Fix from $1,950 2025-01-24
Bootplus HIGH 8.8
CVE-2025-0700

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been rated as critical. Affected by this issue…

Fix: after 2020-08-24
Fix from $1,950 2025-01-24
Bootplus HIGH 8.8
CVE-2025-0701

A vulnerability classified as critical has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This affects an unknown p…

Fix: after 2020-08-24
Fix from $1,950 2025-01-24
Bootplus HIGH 8.8
CVE-2025-0698

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified as critical. Affected is an un…

Fix: after 2020-08-24
Fix from $1,950 2025-01-24
Bootplus HIGH 8.8
CVE-2025-0699

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vu…

Fix: after 2020-08-24
Fix from $1,950 2025-01-24
Simple Downloads List MEDIUM 6.5
CVE-2024-13594

The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofix_sdl' shortcode in all versi…

Fix: 1.4.3+
Fix from $1,600 2025-01-24
Form Builder Cp MEDIUM 6.5
CVE-2024-13680

The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in al…

Fix: 1.2.42+
Fix from $1,600 2025-01-24
Centreon Web HIGH 7.2
CVE-2024-55573

An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A …

Fix: 23.04.24 / 23.10.19+
Fix from $1,950 2025-01-23
Centreon Web HIGH 7.2
CVE-2024-53923

An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with…

Fix: 23.04.24 / 23.10.19+
Fix from $1,950 2025-01-23
Online Food Ordering System CRITICAL 9.8
CVE-2024-57328

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields usernam…

No fix yet
Fix from $2,300 2025-01-23
Unclassified CRITICAL 10.0
CVE-2024-55971

SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauthenticated user to run arbitra…

Mitigation only
Fix from $2,300 2025-01-23
Tainacan MEDIUM 6.5
CVE-2024-13236

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due …

Fix: 0.21.13+
Fix from $1,600 2025-01-23
Product Table CRITICAL 9.8
CVE-2024-13234

The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and inclu…

Fix: 2.1.3+
Fix from $2,300 2025-01-23
Unclassified CRITICAL 9.8
CVE-2023-37777

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to imprope…

Mitigation only
Fix from $2,300 2025-01-22
Unclassified HIGH 8.5
CVE-2025-23910

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in keighl Menus Plus+ menus-plus allows SQL Inject…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified CRITICAL 9.3
CVE-2025-23931

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliver Fuhrmann WordPress Local SEO dh-local-se…

Mitigation only
Fix from $2,300 2025-01-22
Unclassified HIGH 7.6
CVE-2025-23784

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Jeffrey Contact Form 7 Round Robin Lead D…

Mitigation only
Fix from $1,950 2025-01-22
Senayan Library Management System Bulian MEDIUM 6.7
CVE-2025-22980

A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admi…

No fix yet
Fix from $1,600 2025-01-22