Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Real Estate Management System HIGH 7.2
CVE-2025-14898

A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderde…

No fix yet
Fix from $1,950 2025-12-19
Real Estate Management System HIGH 7.2
CVE-2025-14897

A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/userage…

No fix yet
Fix from $1,950 2025-12-19
Phpmsadmin MEDIUM 5.4
CVE-2025-63948

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the …

No fix yet
Fix from $1,600 2025-12-18
Webaccess\/scada HIGH 8.8
CVE-2025-46268

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

Mitigation only
Fix from $1,950 2025-12-18
Unclassified MEDIUM 5.4
CVE-2023-53935

WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.…

No fix yet
Fix from $1,600 2025-12-18
Xperience HIGH 8.8
CVE-2021-47711

A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method par…

Fix: after 13.0.52
Fix from $1,950 2025-12-18
Supplier Management System CRITICAL 9.8
CVE-2025-14877

A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified HIGH 8.5
CVE-2025-64371

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL I…

Mitigation only
Fix from $1,950 2025-12-18
Unclassified CRITICAL 9.3
CVE-2025-60062

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-wit…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.3
CVE-2025-58951

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management fo…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified HIGH 8.5
CVE-2025-14314

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit popup-builder-block allows Blin…

Mitigation only
Fix from $1,950 2025-12-18
Online Appointment Booking System CRITICAL 9.8
CVE-2025-14833

A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /…

Mitigation only
Fix from $2,300 2025-12-17
Simple Stock System HIGH 8.8
CVE-2025-14834

A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a man…

No fix yet
Fix from $1,950 2025-12-17
Simple Cms CRITICAL 9.8
CVE-2023-53926

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database querie…

Mitigation only
Fix from $2,300 2025-12-17
Affiliate Me MEDIUM 6.5
CVE-2023-53917

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate da…

No fix yet
Fix from $1,600 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-68400

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` i…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-68111

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-68112

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-67877

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14832

A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduc…

Mitigation only
Fix from $2,300 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-66396

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-66395

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Covid Tracking System Using Qr Code HIGH 7.3
CVE-2025-67285

A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for …

No fix yet
Fix from $1,950 2025-12-17
Unclassified MEDIUM 6.3
CVE-2025-14780

A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /disht…

Mitigation only
Fix from $1,600 2025-12-16
Unclassified HIGH 8.5
CVE-2025-68054

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Back…

Mitigation only
Fix from $1,950 2025-12-16
Unclassified HIGH 8.5
CVE-2025-68055

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL…

Mitigation only
Fix from $1,950 2025-12-16
Unclassified HIGH 8.5
CVE-2025-68056

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominouts…

Mitigation only
Fix from $1,950 2025-12-16
Unclassified HIGH 7.6
CVE-2025-67999

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blin…

Mitigation only
Fix from $1,950 2025-12-16
Unclassified HIGH 8.5
CVE-2025-68053

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows …

Mitigation only
Fix from $1,950 2025-12-16
Unclassified HIGH 8.5
CVE-2025-67950

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-…

Mitigation only
Fix from $1,950 2025-12-16