Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Gamipress HIGH 7.5
CVE-2024-13496

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL …

Fix: 7.2.2+
Fix from $1,950 2025-01-22
Wp Polls MEDIUM 5.3
CVE-2024-13426

The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping…

Fix: 2.77.3+
Fix from $1,600 2025-01-22
Pearprojectapi CRITICAL 9.8
CVE-2023-27112

pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.

No fix yet
Fix from $2,300 2025-01-21
Pearprojectapi CRITICAL 9.8
CVE-2023-27113

pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at project.php.

No fix yet
Fix from $2,300 2025-01-21
Unclassified HIGH 7.6
CVE-2025-22710

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-…

Mitigation only
Fix from $1,950 2025-01-21
Taskbuilder HIGH 8.8
CVE-2025-22716

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows SQL …

Fix: 3.0.7+
Fix from $1,950 2025-01-21
Unclassified CRITICAL 9.3
CVE-2025-22553

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in dhananjaysingh Multiple Carousel multicarousel …

Mitigation only
Fix from $2,300 2025-01-21
Unclassified CRITICAL 9.3
CVE-2024-51818EPSS 16%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-de…

Mitigation only
Fix from $2,300 2025-01-21
Unclassified HIGH 8.5
CVE-2024-49333

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress …

Mitigation only
Fix from $1,950 2025-01-21
Unclassified CRITICAL 9.3
CVE-2024-49655

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ARPrice arprice allows SQL In…

Mitigation only
Fix from $2,300 2025-01-21
Unclassified HIGH 8.5
CVE-2024-49666

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ARPrice arprice allows SQL In…

Mitigation only
Fix from $1,950 2025-01-21
Unclassified HIGH 8.5
CVE-2024-49303

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress …

No fix yet
Fix from $1,950 2025-01-21
Super Socializer MEDIUM 5.3
CVE-2024-13230

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘Sup…

Fix: 7.14.1+
Fix from $1,600 2025-01-21
Wegia CRITICAL 9.8
CVE-2025-23218

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.2.10+
Fix from $2,300 2025-01-20
Wegia CRITICAL 9.8
CVE-2025-23219

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.2.10+
Fix from $2,300 2025-01-20
Wegia CRITICAL 9.8
CVE-2025-23220

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified…

Fix: 3.2.10+
Fix from $2,300 2025-01-20
A\+hrd CRITICAL 9.8
CVE-2025-0585

The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to re…

Fix: after 7.5
Fix from $2,300 2025-01-20
Unclassified HIGH 7.3
CVE-2025-0579

A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functi…

Mitigation only
Fix from $1,950 2025-01-20
Zzcms CRITICAL 9.8
CVE-2025-0565

A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. …

No fix yet
Fix from $2,300 2025-01-19
Fantasy Cricket CRITICAL 9.8
CVE-2025-0564

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $2,300 2025-01-19
Gym Management System CRITICAL 9.8
CVE-2025-0562

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /d…

No fix yet
Fix from $2,300 2025-01-19
Fantasy Cricket CRITICAL 9.8
CVE-2025-0563

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been classified as critical. Affected is an unknown function of the file /dash…

No fix yet
Fix from $2,300 2025-01-19
Farm Management System CRITICAL 9.8
CVE-2025-0561

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

No fix yet
Fix from $2,300 2025-01-19
Tduck Platform CRITICAL 9.8
CVE-2025-0558

A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest…

Fix: after 4.0
Fix from $2,300 2025-01-18
Unclassified HIGH 7.5
CVE-2024-13184

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all …

Mitigation only
Fix from $1,950 2025-01-18
Ultimate Member HIGH 7.5
CVE-2025-0308

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.9.2+
Fix from $1,950 2025-01-18
Gym Management System CRITICAL 9.8
CVE-2025-0541

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /d…

No fix yet
Fix from $2,300 2025-01-17
Tailoring Management System CRITICAL 9.8
CVE-2025-0540

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of…

No fix yet
Fix from $2,300 2025-01-17
Wegia CRITICAL 9.8
CVE-2024-57035

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

No fix yet
Fix from $2,300 2025-01-17
Wegia CRITICAL 9.8
CVE-2024-57034

WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

Fix: 3.2.0+
Fix from $2,300 2025-01-17