Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 8.2
CVE-2021-47777

Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attacke…

No fix yet
Fix from $1,950 2026-01-15
Unclassified HIGH 7.1
CVE-2021-47766

Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipula…

No fix yet
Fix from $1,950 2026-01-15
Unclassified HIGH 8.2
CVE-2021-47763

Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries…

No fix yet
Fix from $1,950 2026-01-15
Invoiceplane MEDIUM 6.5
CVE-2025-67082

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a repo…

Fix: 1.6.4+
Fix from $1,600 2026-01-15
Unclassified HIGH 7.5
CVE-2025-12166

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `ord…

Mitigation only
Fix from $1,950 2026-01-14
Edgeconnect Sd Wan Orchestrator HIGH 7.2
CVE-2025-37182

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL …

Fix: 9.5.6+
Fix from $1,950 2026-01-14
Edgeconnect Sd Wan Orchestrator HIGH 7.2
CVE-2025-37183

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL …

Fix: 9.5.6+
Fix from $1,950 2026-01-14
Edgeconnect Sd Wan Orchestrator HIGH 7.2
CVE-2025-37181

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL …

Fix: 9.5.6+
Fix from $1,950 2026-01-14
Camel MEDIUM 5.3
CVE-2025-66169

Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before…

Fix: 4.10.8 / 4.14.3+
Fix from $1,600 2026-01-14
Unclassified HIGH 7.5
CVE-2025-14770

The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions up to, and including, 2.0.0 …

Mitigation only
Fix from $1,950 2026-01-14
Unclassified HIGH 8.2
CVE-2023-54340

WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and passwor…

No fix yet
Fix from $1,950 2026-01-13
Unclassified HIGH 8.2
CVE-2023-54333

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database q…

No fix yet
Fix from $1,950 2026-01-13
Wallpaper Admin MEDIUM 6.5
CVE-2022-50894

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting …

No fix yet
Fix from $1,600 2026-01-13
Aerocms CRITICAL 9.8
CVE-2022-50895

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exp…

Mitigation only
Fix from $2,300 2026-01-13
Wallpaper Admin CRITICAL 9.8
CVE-2022-50892

VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials.…

Mitigation only
Fix from $2,300 2026-01-13
Unclassified HIGH 8.2
CVE-2022-50805

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL…

No fix yet
Fix from $1,950 2026-01-13
Sharepoint Server HIGH 8.8
CVE-2026-20947EPSS 19%

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20442+
Fix from $1,950 2026-01-13
Forticlientems HIGH 7.2
CVE-2025-59922EPSS 7%

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientE…

Fix: 7.2.12 / 7.4.5+
Fix from $1,950 2026-01-13
News Portal CRITICAL 9.8
CVE-2025-69991

phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

No fix yet
Fix from $2,300 2026-01-13
Flowmon Anomaly Detection System HIGH 8.8
CVE-2025-13774

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to…

Fix: after 13.0.1
Fix from $1,950 2026-01-13
Unclassified CRITICAL 9.9
CVE-2026-0501

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute cra…

Mitigation only
Fix from $2,300 2026-01-13
Gym Management System CRITICAL 9.4
CVE-2025-67146

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) train…

No fix yet
Fix from $2,300 2026-01-12
Unclassified CRITICAL 9.8
CVE-2025-67147

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1…

Mitigation only
Fix from $2,300 2026-01-12
Online Exam System CRITICAL 9.1
CVE-2025-51567

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary…

No fix yet
Fix from $2,300 2026-01-12
Unclassified HIGH 8.7
CVE-2025-41005

Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.

Mitigation only
Fix from $1,950 2026-01-12
Unclassified CRITICAL 9.3
CVE-2025-41006

Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

Mitigation only
Fix from $2,300 2026-01-12
Unclassified HIGH 8.7
CVE-2025-41004

Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’…

Mitigation only
Fix from $1,950 2026-01-12
Iot Edge Linux Docker CRITICAL 9.8
CVE-2025-52694EPSS 38%

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vu…

Fix: 2.0.2 / 3.4.15+
Fix from $2,300 2026-01-12
Online Music Site CRITICAL 9.8
CVE-2026-0852

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH…

Mitigation only
Fix from $2,300 2026-01-12
Online Music Site CRITICAL 9.8
CVE-2026-0851

A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/Adm…

Mitigation only
Fix from $2,300 2026-01-12