Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.3
CVE-2026-1449

A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XF…

Mitigation only
Fix from $1,950 2026-01-27
Expressionengine HIGH 7.2
CVE-2025-59473

SQL Injection vulnerability in the Structure for Admin authenticated user

Fix: 7.5.14+
Fix from $1,950 2026-01-26
Online Music Site CRITICAL 9.8
CVE-2026-1443

A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/Adm…

Mitigation only
Fix from $2,300 2026-01-26
Online Examination System CRITICAL 9.8
CVE-2026-1422

A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /ind…

Mitigation only
Fix from $2,300 2026-01-26
Unclassified MEDIUM 6.8
CVE-2025-14973

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing cont…

Mitigation only
Fix from $1,600 2026-01-26
Gemscms Backend CRITICAL 9.4
CVE-2025-52025

An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulner…

Fix: after 2025-05-28
Fix from $2,300 2026-01-23
Unclassified HIGH 7.6
CVE-2026-24624

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL I…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 8.5
CVE-2026-24572

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio Content nelio-content allo…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 8.3
CVE-2026-0603

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially …

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 8.5
CVE-2026-24367

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL I…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.6
CVE-2026-22470

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real E…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.5
CVE-2025-69180

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra Portfolio ultra-portfolio al…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.5
CVE-2025-69045

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FooEvents FooEvents for WooCommerce fooevents a…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.5
CVE-2025-68999

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-e…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.5
CVE-2025-68881

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Inj…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-68857

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Downloads paid-downloads allows …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified HIGH 7.5
CVE-2025-68017

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Email Validator antideo-email-v…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-68034

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp all…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-67945

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified HIGH 8.5
CVE-2025-49049

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allow…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.5
CVE-2025-49050

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-49055

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca…

Mitigation only
Fix from $2,300 2026-01-22
Unisphere For Powermax HIGH 8.8
CVE-2025-36588

Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') …

Fix: 9.2.4.19+
Fix from $1,950 2026-01-22
Hotel Guest Hotspot HIGH 8.8
CVE-2025-4764

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel…

Fix: after 2026-01-22
Fix from $1,950 2026-01-22
On Prem Enterprise Server CRITICAL 9.8
CVE-2025-27378

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this …

Fix: 7.0.6+
Fix from $2,300 2026-01-22
Unclassified HIGH 7.1
CVE-2021-47872

SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipula…

No fix yet
Fix from $1,950 2026-01-21
Unclassified HIGH 8.2
CVE-2021-47848

Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username p…

No fix yet
Fix from $1,950 2026-01-21
Unclassified HIGH 8.2
CVE-2021-47846

Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated…

No fix yet
Fix from $1,950 2026-01-21
Retail Point Of Sale MEDIUM 6.5
CVE-2025-67261

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the Ord…

Mitigation only
Fix from $1,600 2026-01-20
Ksoa CRITICAL 9.8
CVE-2026-1179

A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter H…

Mitigation only
Fix from $2,300 2026-01-19