Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Ksoa CRITICAL 9.8
CVE-2026-1177

A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/save_folder.jsp of the…

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1178

A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /kmf/select.jsp of th…

Mitigation only
Fix from $2,300 2026-01-19
School Management System CRITICAL 9.8
CVE-2026-1176

A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the file /subject/index.php. Per…

Mitigation only
Fix from $2,300 2026-01-19
Koko Analytics HIGH 8.3
CVE-2026-22850

Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped …

Fix: 2.1.3+
Fix from $1,950 2026-01-19
Directory Management System CRITICAL 9.8
CVE-2026-1160

A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of t…

Mitigation only
Fix from $2,300 2026-01-19
Devolutions Server CRITICAL 9.8
CVE-2026-0610

SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

Fix: 2025.3.14.0+
Fix from $2,300 2026-01-19
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-1159

A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This issue affects some unknown processing of the file /order…

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1133

A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET …

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1132

A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET …

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1131

A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parame…

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1130

A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP G…

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1129

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GE…

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1124

A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1123

A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Para…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1120

A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component H…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1121

A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Para…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1122

A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Pa…

Mitigation only
Fix from $2,300 2026-01-18
Society Management System CRITICAL 9.8
CVE-2026-1119

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/delete_activity.p…

Mitigation only
Fix from $2,300 2026-01-18
Society Management System CRITICAL 9.8
CVE-2026-1118

A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/add_activity.php. Perf…

Mitigation only
Fix from $2,300 2026-01-18
Easycms CRITICAL 9.8
CVE-2026-1105

A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of …

Fix: after 1.6
Fix from $2,300 2026-01-18
Warehouse Management System CRITICAL 9.8
CVE-2026-1059

A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknow…

Fix: after 2021-11-15
Fix from $2,300 2026-01-17
Unclassified HIGH 7.3
CVE-2026-1050

A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/r…

Mitigation only
Fix from $1,950 2026-01-17
Wegia HIGH 7.2
CVE-2026-23723

WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was identified in the Atendido_ocorr…

Fix: 3.6.2+
Fix from $1,950 2026-01-16
Process Optimization HIGH 7.8
CVE-2025-61943

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Hist…

Fix: 2025+
Fix from $1,950 2026-01-16
Grocery Crud CRITICAL 9.1
CVE-2021-47811

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Atta…

Fix: 2.0.1+
Fix from $2,300 2026-01-16
Unclassified HIGH 8.2
CVE-2021-47801

Vianeos OctoPUS 5 contains a time-based blind SQL injection vulnerability in the 'login_user' parameter during authentication requests. Attackers can…

No fix yet
Fix from $1,950 2026-01-16
Unclassified HIGH 8.2
CVE-2021-47782

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicio…

No fix yet
Fix from $1,950 2026-01-16
Cyber Cafe Management System CRITICAL 9.8
CVE-2025-70892

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly …

Mitigation only
Fix from $2,300 2026-01-15
Cyber Cafe Management System HIGH 8.8
CVE-2025-70893

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The appli…

No fix yet
Fix from $1,950 2026-01-15
Glpi CRITICAL 9.8
CVE-2025-66417

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…

Fix: 11.0.3+
Fix from $2,300 2026-01-15