Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.2
CVE-2025-13192

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to generic …

Mitigation only
Fix from $1,950 2026-02-05
Facturascripts HIGH 8.8
CVE-2026-25514

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL …

Fix: 2025.81+
Fix from $1,950 2026-02-04
Facturascripts HIGH 8.8
CVE-2026-25513

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL …

Fix: 2025.81+
Fix from $1,950 2026-02-04
Glpi HIGH 8.8
CVE-2026-22044

GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This…

Fix: 10.0.23+
Fix from $1,950 2026-02-04
Openstamanager HIGH 8.8
CVE-2025-69213

OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerabilit…

Fix: after 2.9.8
Fix from $1,950 2026-02-04
Openstamanager HIGH 8.8
CVE-2025-69215

OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vul…

Fix: after 2.9.8
Fix from $1,950 2026-02-04
Unclassified CRITICAL 9.8
CVE-2025-5329

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation …

Mitigation only
Fix from $2,300 2026-02-04
Unclassified HIGH 7.5
CVE-2025-15268

The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API action in all versions up to,…

Mitigation only
Fix from $1,950 2026-02-04
Unclassified HIGH 8.2
CVE-2020-37083

PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through t…

No fix yet
Fix from $1,950 2026-02-03
School Erp Pro CRITICAL 9.8
CVE-2020-37089

School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu…

Mitigation only
Fix from $2,300 2026-02-03
Victor Cms HIGH 8.2
CVE-2020-37076

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database…

No fix yet
Fix from $1,950 2026-02-03
Unclassified HIGH 7.1
CVE-2020-37081

Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers t…

No fix yet
Fix from $1,950 2026-02-03
Unclassified HIGH 8.2
CVE-2019-25260

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious da…

No fix yet
Fix from $1,950 2026-02-03
Fikir Odalari Adminpando CRITICAL 10.0
CVE-2025-10878

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parame…

Fix: after 1.0.1
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25238

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription d…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb HIGH 7.5
CVE-2026-25239

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue inser…

Fix: 1.33.0+
Fix from $1,950 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25240

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::ma…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25241

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<packa…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25236

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25234

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion …

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Jeewms MEDIUM 6.5
CVE-2025-70311

JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do …

Mitigation only
Fix from $1,600 2026-02-03
Iot Smart Water Meter Firmware CRITICAL 9.8
CVE-2025-63624

SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute…

Mitigation only
Fix from $2,300 2026-02-03
Cpas Audit Management System CRITICAL 9.8
CVE-2025-57529

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validatio…

Fix: after 4.9
Fix from $2,300 2026-02-03
60cyclecms CRITICAL 9.8
CVE-2020-37110

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through …

Mitigation only
Fix from $2,300 2026-02-03
Open Eclass Platform MEDIUM 6.5
CVE-2020-37112

GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unva…

No fix yet
Fix from $1,600 2026-02-03
Unclassified HIGH 7.1
CVE-2020-37105

PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL com…

No fix yet
Fix from $1,950 2026-02-03
Unclassified HIGH 7.1
CVE-2020-37108

PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows remote attackers to manipulate…

No fix yet
Fix from $1,950 2026-02-03
Unclassified HIGH 8.5
CVE-2026-25022

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-manageme…

Mitigation only
Fix from $1,950 2026-02-03
Django MEDIUM 5.4
CVE-2026-1207EPSS 13%

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS…

Fix: 4.2.28 / 5.2.11+
Fix from $1,600 2026-02-03
Django MEDIUM 5.4
CVE-2026-1287

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column alias…

Fix: 4.2.28 / 5.2.11+
Fix from $1,600 2026-02-03