Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.5
CVE-2024-11939

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, …

Mitigation only
Fix from $1,950 2025-01-08
Wordpress Meta Data And Taxonomies Filter MEDIUM 6.5
CVE-2024-12030

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute of the 'mdf_value' shortcode i…

Fix: 1.3.3.6+
Fix from $1,600 2025-01-08
Unclassified HIGH 7.6
CVE-2025-22350

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injec…

Mitigation only
Fix from $1,950 2025-01-07
Online Book Shop HIGH 8.8
CVE-2025-0300

A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of…

No fix yet
Fix from $1,950 2025-01-07
Online Book Shop CRITICAL 9.8
CVE-2025-0299

A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_resu…

No fix yet
Fix from $2,300 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22536

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiren.sabd WP Music Player wp-music-player allo…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22533

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bulktheme WOOEXIM wooexim allows SQL Injection.…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 8.5
CVE-2025-22519

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jerodmoore eDoc Easy Tables edoc-easy-tables al…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22507

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in iDo8p WPMU Prefill Post wpmu-prefill-post allow…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22502

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mindvalley MindValley Super PageMash mindvalley…

Mitigation only
Fix from $1,950 2025-01-07
Online Book Shop CRITICAL 9.8
CVE-2025-0298

A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the fil…

No fix yet
Fix from $2,300 2025-01-07
Online Book Shop MEDIUM 6.3
CVE-2025-0297

A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the fil…

No fix yet
Fix from $1,600 2025-01-07
Vehicle Management System HIGH 7.2
CVE-2024-48245

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, …

Mitigation only
Fix from $1,950 2025-01-07
Online Book Shop CRITICAL 9.8
CVE-2025-0296

A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /bookli…

No fix yet
Fix from $2,300 2025-01-07
Home Clean Services Management System HIGH 8.8
CVE-2025-0294

A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability…

No fix yet
Fix from $1,950 2025-01-07
Unclassified HIGH 8.5
CVE-2025-22348

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rtowebsites DynamicTags dynamictags allows Blin…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22349

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress Auction Plugin wp-auctions a…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22351

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contact Form 7 Database – CFDB7 adv…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.6
CVE-2025-22352

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edi…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified CRITICAL 9.3
CVE-2024-56290

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing …

Mitigation only
Fix from $2,300 2025-01-07
Unclassified CRITICAL 9.3
CVE-2024-56284

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wireless SMS Notification ssl-wi…

Mitigation only
Fix from $2,300 2025-01-07
Clickwhale HIGH 8.5
CVE-2024-51715

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale clickwhale allows Blind S…

Fix: 2.4.2+
Fix from $1,950 2025-01-07
Wordpress Auction CRITICAL 9.8
CVE-2024-8855

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing edito…

Fix: after 3.7
Fix from $2,300 2025-01-07
Wpschoolpress MEDIUM 6.5
CVE-2024-12332

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and i…

Fix: after 2.2.14
Fix from $1,600 2025-01-07
Unclassified HIGH 7.5
CVE-2024-12157

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.5
CVE-2024-12416

The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woomotiv_seen_products_.*' cookie…

Mitigation only
Fix from $1,950 2025-01-07
Email Subscribers \& Newsletters MEDIUM 6.5
CVE-2024-12311

The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement,…

Fix: 5.7.44+
Fix from $1,600 2025-01-06
Project Management System CRITICAL 9.8
CVE-2025-0233

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pa…

No fix yet
Fix from $2,300 2025-01-05
Gym Management System HIGH 8.8
CVE-2025-0231

A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $1,950 2025-01-05
Blood Bank Management System HIGH 8.8
CVE-2025-0232

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionali…

No fix yet
Fix from $1,950 2025-01-05