Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified MEDIUM 6.3
CVE-2025-0404

A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the function CoachController of the…

Mitigation only
Fix from $1,600 2025-01-13
Gymxmjpa HIGH 8.8
CVE-2025-0405

A vulnerability was found in liujianview gymxmjpa 1.0 and classified as critical. This issue affects the function GoodsDaoImpl of the file src/main/j…

No fix yet
Fix from $1,950 2025-01-13
Jeewms HIGH 8.8
CVE-2025-0392

A vulnerability, which was classified as critical, was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. Affected is the functio…

Fix: 2025-01-01+
Fix from $1,950 2025-01-11
Jeewms HIGH 8.8
CVE-2025-0391

A vulnerability, which was classified as critical, has been found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This issue affects…

Fix: 2025-01-01+
Fix from $1,950 2025-01-11
Expedition HIGH 8.8
CVE-2025-0103

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as pas…

Fix: 1.2.101+
Fix from $1,950 2025-01-11
Unclassified HIGH 7.5
CVE-2024-12404

The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all versions up to, and includin…

Mitigation only
Fix from $1,950 2025-01-11
Ng Firewall HIGH 8.3
CVE-2024-9134

Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL…

Fix: 17.2+
Fix from $1,950 2025-01-10
Unclassified MEDIUM 6.5
CVE-2024-12473

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin fo…

Mitigation only
Fix from $1,600 2025-01-10
Ruoyi MEDIUM 6.3
CVE-2024-54762

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter S…

Fix: after 4.7.9
Fix from $1,600 2025-01-09
Bigant Office Messenger 5 MEDIUM 6.3
CVE-2024-54761

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

No fix yet
Fix from $1,600 2025-01-09
Chatwoot HIGH 8.8
CVE-2025-21628

Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator pas…

Fix: 3.16.0+
Fix from $1,950 2025-01-09
Unclassified HIGH 8.5
CVE-2025-22535

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal wplistcal allows SQL Injectio…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.5
CVE-2025-22537

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-map…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified CRITICAL 9.3
CVE-2025-22540

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in seballero Emailing Subscription email-suscripci…

Mitigation only
Fix from $2,300 2025-01-09
Unclassified CRITICAL 9.3
CVE-2025-22542

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ofek Nakar Virtual Bot virtual-bot allows Blind…

Mitigation only
Fix from $2,300 2025-01-09
Unclassified HIGH 8.5
CVE-2025-22505

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlis…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 7.6
CVE-2025-22527

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified MEDIUM 6.5
CVE-2024-12067

The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary…

Mitigation only
Fix from $1,600 2025-01-09
Admission Management System CRITICAL 9.8
CVE-2025-0347

A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulnerability affects unknown code…

No fix yet
Fix from $2,300 2025-01-09
Cy Fast HIGH 8.8
CVE-2025-0345

A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function listData of the file /sys/menu/li…

No fix yet
Fix from $1,950 2025-01-09
Cy Fast HIGH 8.8
CVE-2025-0344

A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file…

No fix yet
Fix from $1,950 2025-01-09
Cinema Seat Reservation System CRITICAL 9.8
CVE-2025-0340

A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown fu…

Mitigation only
Fix from $2,300 2025-01-09
Project Management System CRITICAL 9.8
CVE-2025-0336

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pa…

No fix yet
Fix from $2,300 2025-01-09
Cy Fast HIGH 8.8
CVE-2025-0334

A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file…

No fix yet
Fix from $1,950 2025-01-09
Cy Fast HIGH 8.8
CVE-2025-0333

A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData…

No fix yet
Fix from $1,950 2025-01-09
E Commerce Php HIGH 8.0
CVE-2024-13204

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $1,950 2025-01-09
Sucms HIGH 8.8
CVE-2024-13194

A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_memb…

No fix yet
Fix from $1,950 2025-01-09
Wegia HIGH 8.8
CVE-2025-22141

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, s…

Fix: 3.2.8+
Fix from $1,950 2025-01-08
Wegia HIGH 8.8
CVE-2025-22140

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php en…

Fix: 3.2.8+
Fix from $1,950 2025-01-08
Unclassified HIGH 8.8
CVE-2024-55517

An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGC…

Mitigation only
Fix from $1,950 2025-01-08