Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Intern Membership Management System HIGH 7.2
CVE-2026-0850

A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_ac…

No fix yet
Fix from $1,950 2026-01-11
Unclassified MEDIUM 6.3
CVE-2026-0843

A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerability affects unknown code of t…

Mitigation only
Fix from $1,600 2026-01-11
Full Calendar Macro CRITICAL 10.0
CVE-2025-65091

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONServi…

Fix: 2.4.5+
Fix from $2,300 2026-01-10
Weknora CRITICAL 9.8
CVE-2026-22687

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables th…

Fix: 0.2.5+
Fix from $2,300 2026-01-10
Ghost HIGH 7.2
CVE-2026-22596

Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admi…

Fix: 5.130.6 / 6.11.0+
Fix from $1,950 2026-01-10
Pss.sale.com MEDIUM 6.5
CVE-2025-51626

SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

Mitigation only
Fix from $1,600 2026-01-09
Rhapsode MEDIUM 6.5
CVE-2025-67811

Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient input validation allows remote …

Mitigation only
Fix from $1,600 2026-01-09
Gestsup HIGH 8.1
CVE-2026-22196

GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket…

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Gestsup HIGH 8.1
CVE-2026-22197

GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to …

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Gestsup HIGH 8.1
CVE-2026-22195

GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated …

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Docsys HIGH 8.8
CVE-2025-15494

A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. T…

Fix: after 2.02.37
Fix from $1,950 2026-01-09
Yshopmall CRITICAL 9.8
CVE-2025-15496

A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of th…

Fix: after 1.9.1
Fix from $2,300 2026-01-09
Docsys CRITICAL 9.8
CVE-2025-15493

A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMa…

Fix: after 2.02.36
Fix from $2,300 2026-01-09
Tim Flow MEDIUM 5.4
CVE-2025-67281

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access…

Fix: 9.1.2+
Fix from $1,600 2026-01-09
Online Course Registration System HIGH 8.8
CVE-2026-0803

A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipu…

Fix: after 3.1
Fix from $1,950 2026-01-09
Docsys HIGH 8.8
CVE-2025-15492

A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/Grou…

Fix: after 2.02.36
Fix from $1,950 2026-01-09
Bet E Portal CRITICAL 9.8
CVE-2025-14598

BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables ar…

Mitigation only
Fix from $2,300 2026-01-09
Icx500 Firmware HIGH 7.5
CVE-2025-64092

This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database.

Fix: 1.4.3.3+
Fix from $1,950 2026-01-09
Online Course Registration System HIGH 8.8
CVE-2026-0733

A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/…

Fix: after 3.1
Fix from $1,950 2026-01-09
Intern Membership Management System HIGH 7.2
CVE-2026-0729

A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_…

No fix yet
Fix from $1,950 2026-01-08
Intern Membership Management System HIGH 7.2
CVE-2026-0728

A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of th…

No fix yet
Fix from $1,950 2026-01-08
Online Shopping System CRITICAL 9.8
CVE-2025-61246

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

Mitigation only
Fix from $2,300 2026-01-08
Print Shop Pro Webdesk CRITICAL 9.8
CVE-2025-61548

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions…

Mitigation only
Fix from $2,300 2026-01-08
Parsl HIGH 7.3
CVE-2026-21892

Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. …

Fix: 2026.01.05+
Fix from $1,950 2026-01-08
Unclassified HIGH 8.5
CVE-2025-67921

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.…

Mitigation only
Fix from $1,950 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-67928

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allow…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified HIGH 8.5
CVE-2025-22728

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap a…

Mitigation only
Fix from $1,950 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-23993

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allow…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified HIGH 8.5
CVE-2025-22713

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporte…

Mitigation only
Fix from $1,950 2026-01-08
Intern Membership Management System HIGH 7.2
CVE-2026-0701

A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality o…

No fix yet
Fix from $1,950 2026-01-08