Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Unclassified HIGH 7.6
CVE-2025-67962

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team Broken Link Checker broken-l…

Mitigation only
Fix from $1,950 2025-12-16
Qts CRITICAL 9.8
CVE-2025-62849

An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…

Mitigation only
Fix from $2,300 2025-12-16
Churchcrm HIGH 7.2
CVE-2025-67751

ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. Whe…

Fix: 6.5.0+
Fix from $1,950 2025-12-16
Freepbx HIGH 7.2
CVE-2025-67736EPSS 6%

The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to…

Fix: 16.0.5 / 17.0.5+
Fix from $1,950 2025-12-16
Bus Reservation System CRITICAL 9.8
CVE-2023-53877

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. At…

Mitigation only
Fix from $2,300 2025-12-15
Inventory Management System MEDIUM 5.3
CVE-2023-36338

Inventory Management System 1 was discovered to contain a SQL injection vulnerability.

No fix yet
Fix from $1,600 2025-12-15
News Buzz MEDIUM 5.3
CVE-2023-38913

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

No fix yet
Fix from $1,600 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66439

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.p…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66440

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/p…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Unclassified HIGH 7.5
CVE-2025-14383

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, a…

Mitigation only
Fix from $1,950 2025-12-15
Unclassified HIGH 8.7
CVE-2025-34179

NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. Th…

Mitigation only
Fix from $1,950 2025-12-15
Hotels Server CRITICAL 9.8
CVE-2025-14710

A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /…

Fix: after 2019-03-23
Fix from $2,300 2025-12-15
Hotels Server CRITICAL 9.8
CVE-2025-14711

A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the fi…

Fix: after 2019-03-23
Fix from $2,300 2025-12-15
Advanced Online Examination System CRITICAL 9.8
CVE-2025-14668

A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. P…

Mitigation only
Fix from $2,300 2025-12-14
Covid Tracking System CRITICAL 9.8
CVE-2025-14666

A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. …

Mitigation only
Fix from $2,300 2025-12-14
Covid Tracking System CRITICAL 9.8
CVE-2025-14667

A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/…

Mitigation only
Fix from $2,300 2025-12-14
Supplier Management System CRITICAL 9.8
CVE-2025-14664

A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.p…

Mitigation only
Fix from $2,300 2025-12-14
Student Management System CRITICAL 9.8
CVE-2025-14661

A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown functionality of the file /advise…

Mitigation only
Fix from $2,300 2025-12-14
Student Management System CRITICAL 9.8
CVE-2025-14653

A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipu…

Mitigation only
Fix from $2,300 2025-12-14
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14652

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?ac…

Mitigation only
Fix from $2,300 2025-12-14
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14650

A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing mani…

Mitigation only
Fix from $2,300 2025-12-14
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14649

A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakes…

Mitigation only
Fix from $2,300 2025-12-14
Computer Book Store CRITICAL 9.8
CVE-2025-14647

A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipula…

Mitigation only
Fix from $2,300 2025-12-14
Student File Management System CRITICAL 9.8
CVE-2025-14645

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of the file /admin/delete_user.p…

Mitigation only
Fix from $2,300 2025-12-14
Student File Management System CRITICAL 9.8
CVE-2025-14646

A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown function of the file /admin/delete_s…

Mitigation only
Fix from $2,300 2025-12-14
Unclassified HIGH 7.5
CVE-2025-13126

The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, a…

Mitigation only
Fix from $1,950 2025-12-14
Student Management System CRITICAL 9.8
CVE-2025-14644

A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject…

Mitigation only
Fix from $2,300 2025-12-14
Simple Attendance Record System CRITICAL 9.8
CVE-2025-14643

A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. P…

Mitigation only
Fix from $2,300 2025-12-14
Student File Management System CRITICAL 9.8
CVE-2025-14640

A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_studen…

Mitigation only
Fix from $2,300 2025-12-14
Student Management System CRITICAL 9.8
CVE-2025-14639

A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /uprec.php. Performing manipu…

Mitigation only
Fix from $2,300 2025-12-14