Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
School Management System CRITICAL 9.8
CVE-2026-2073

A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. E…

Mitigation only
Fix from $2,300 2026-02-07
Unclassified HIGH 8.2
CVE-2020-37163

QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter i…

No fix yet
Fix from $1,950 2026-02-07
Unclassified HIGH 7.1
CVE-2020-37147

ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database querie…

No fix yet
Fix from $1,950 2026-02-07
Unclassified HIGH 7.1
CVE-2020-37154

eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database …

No fix yet
Fix from $1,950 2026-02-07
Unclassified HIGH 8.2
CVE-2020-37141

AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manip…

No fix yet
Fix from $1,950 2026-02-07
Payload CRITICAL 9.8
CVE-2026-25544

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly…

Fix: 3.73.0+
Fix from $2,300 2026-02-06
Openstamanager MEDIUM 6.5
CVE-2026-24418

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Err…

Fix: after 2.9.8
Fix from $1,600 2026-02-06
Openstamanager MEDIUM 6.5
CVE-2026-24416

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Tim…

Fix: after 2.9.8
Fix from $1,600 2026-02-06
Openstamanager MEDIUM 6.5
CVE-2026-24417

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Tim…

Fix: after 2.9.8
Fix from $1,600 2026-02-06
Openstamanager HIGH 8.8
CVE-2025-69214

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exi…

Fix: after 2.9.8
Fix from $1,950 2026-02-06
Openstamanager MEDIUM 6.5
CVE-2025-69216

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an authenticated SQL injection vul…

Fix: after 2.9.8
Fix from $1,600 2026-02-06
Simple Blood Donor Management System CRITICAL 9.8
CVE-2026-2060

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of th…

Mitigation only
Fix from $2,300 2026-02-06
Openstamanager MEDIUM 6.5
CVE-2026-24419

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Err…

Fix: after 2.9.8
Fix from $1,600 2026-02-06
Medical Center Portal Management System CRITICAL 9.8
CVE-2026-2059

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.…

Mitigation only
Fix from $2,300 2026-02-06
Cloudclassroom Php Project CRITICAL 9.8
CVE-2026-2058

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of …

Mitigation only
Fix from $2,300 2026-02-06
Unclassified HIGH 7.1
CVE-2019-25299

RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries…

No fix yet
Fix from $1,950 2026-02-06
Unclassified HIGH 7.1
CVE-2019-25300

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter.…

No fix yet
Fix from $1,950 2026-02-06
Unclassified HIGH 7.1
CVE-2019-25303

TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GE…

No fix yet
Fix from $1,950 2026-02-06
Html5 Snmp CRITICAL 9.1
CVE-2019-25298

html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP p…

No fix yet
Fix from $2,300 2026-02-06
Medical Center Portal Management System CRITICAL 9.8
CVE-2026-2057

A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. …

Mitigation only
Fix from $2,300 2026-02-06
School Management System CRITICAL 9.8
CVE-2026-2018

A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This …

Mitigation only
Fix from $2,300 2026-02-06
School Management System CRITICAL 9.8
CVE-2026-2014

A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/ind…

Mitigation only
Fix from $2,300 2026-02-06
School Management System CRITICAL 9.8
CVE-2026-2013

A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. S…

Mitigation only
Fix from $2,300 2026-02-06
School Management System CRITICAL 9.8
CVE-2026-2011

A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment…

Mitigation only
Fix from $2,300 2026-02-06
School Management System CRITICAL 9.8
CVE-2026-2012

A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facul…

Mitigation only
Fix from $2,300 2026-02-06
Forticlientems CRITICAL 9.8
CVE-2026-21643 KEVEPSS 94%

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u…

Mitigation only
Fix from $2,300 2026-02-06
Discover MEDIUM 6.3
CVE-2025-15325

Tanium addressed an improper input validation vulnerability in Discover.

Fix: 4.10.90+
Fix from $1,600 2026-02-05
Phpmychat Plus HIGH 7.5
CVE-2020-37151

phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipu…

No fix yet
Fix from $1,950 2026-02-05
Aspera Console HIGH 8.6
CVE-2025-13379

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…

Fix: after 3.4.8
Fix from $1,950 2026-02-05
Infinera Dna MEDIUM 6.3
CVE-2025-10258

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive…

Mitigation only
Fix from $1,600 2026-02-05