Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Intern Membership Management System HIGH 7.2
CVE-2026-0699

A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_a…

No fix yet
Fix from $1,950 2026-01-08
Intern Membership Management System CRITICAL 9.8
CVE-2026-0700

A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/ch…

Mitigation only
Fix from $2,300 2026-01-08
Intern Membership Management System HIGH 7.2
CVE-2026-0698

A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown function of the file /intern/admin/e…

No fix yet
Fix from $1,950 2026-01-08
Intern Membership Management System HIGH 7.2
CVE-2026-0697

A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown function of the file /intern/admin…

No fix yet
Fix from $1,950 2026-01-08
Clipbucket CRITICAL 9.8
CVE-2026-21875

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the ad…

Fix: 5.5.2-191+
Fix from $2,300 2026-01-08
Unclassified MEDIUM 5.3
CVE-2023-7333

A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Han…

Patch available
Fix from $1,600 2026-01-07
Tarkov Data Manager HIGH 8.8
CVE-2026-21856

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL in…

Fix: 2026-01-02+
Fix from $1,950 2026-01-07
Unclassified CRITICAL 9.3
CVE-2025-32303

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.Th…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified HIGH 8.5
CVE-2025-69351

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allow…

Mitigation only
Fix from $1,950 2026-01-06
Isensix Advanced Remote Monitoring System Firmware HIGH 7.5
CVE-2025-59379

DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL databa…

Fix: after 1.5.7
Fix from $1,950 2026-01-06
Quiz And Survey Master MEDIUM 6.5
CVE-2025-9318

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ par…

Fix: 10.3.2+
Fix from $1,600 2026-01-06
Unclassified MEDIUM 6.5
CVE-2025-14153

The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' shortcode attribute in al…

Mitigation only
Fix from $1,600 2026-01-06
Unclassified MEDIUM 6.5
CVE-2025-13652

The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-01-06
Online Music Site CRITICAL 9.8
CVE-2026-0607

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executi…

Mitigation only
Fix from $2,300 2026-01-06
Online Music Site CRITICAL 9.8
CVE-2026-0606

A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Album…

Mitigation only
Fix from $2,300 2026-01-05
Online Music Site CRITICAL 9.8
CVE-2026-0605

A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.3
CVE-2025-39484

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue …

Mitigation only
Fix from $2,300 2026-01-05
Supplier Management System CRITICAL 9.8
CVE-2026-0597

A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_pr…

Mitigation only
Fix from $2,300 2026-01-05
Awie CRITICAL 9.8
CVE-2025-15029EPSS 11%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)…

Fix: 24.04.3 / 24.10.3+
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0591

A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/c…

Mitigation only
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0592

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown function of the file /handgunner-…

Mitigation only
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0590

A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file /app/c…

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.3
CVE-2025-68865

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows…

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.3
CVE-2025-30633

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations …

Mitigation only
Fix from $2,300 2026-01-05
Unclassified HIGH 8.5
CVE-2025-31044

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SEO Pack allows SQL Injection.T…

Mitigation only
Fix from $1,950 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0583

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/u…

Mitigation only
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0584

A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/pro…

Mitigation only
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0585

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order…

Mitigation only
Fix from $2,300 2026-01-05
Society Management System CRITICAL 9.8
CVE-2026-0582

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_activity_query.php…

Mitigation only
Fix from $2,300 2026-01-05
Qoca Aim MEDIUM 6.5
CVE-2025-15239

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject …

Fix: 2.7.6+
Fix from $1,600 2026-01-05