Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Question Paper Generator HIGH 8.8
CVE-2025-14203

A flaw has been found in code-projects Question Paper Generator up to 1.0. This vulnerability affects unknown code of the file /selectquestionuser.ph…

No fix yet
Fix from $1,950 2025-12-07
Employee Profile Management System HIGH 8.8
CVE-2025-14193

A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_per…

No fix yet
Fix from $1,950 2025-12-07
Unclassified HIGH 7.3
CVE-2025-14192

A vulnerability was found in RashminDungrani online-banking up to 2337ad552ea9d385b4e07b90e6f32d011b7c68a2. This affects an unknown part of the file …

Mitigation only
Fix from $1,950 2025-12-07
Unclassified HIGH 7.3
CVE-2025-14190

A flaw has been found in Chanjet TPlus up to 20251121. Affected by this vulnerability is an unknown functionality of the file /tplus/ajaxpro/Ufida.T.…

Mitigation only
Fix from $1,950 2025-12-07
Unclassified HIGH 7.3
CVE-2025-14189

A vulnerability was detected in Chanjet CRM up to 20251121. Affected is an unknown function of the file /tools/jxf_dump_table_demo.php. The manipulat…

Mitigation only
Fix from $1,950 2025-12-07
Unclassified MEDIUM 6.3
CVE-2025-14185

A vulnerability was identified in Yonyou U8 Cloud 5.0/5.0sp/5.1/5.1sp. The affected element is an unknown function of the file nc/pubitf/erm/mobile/a…

Mitigation only
Fix from $1,600 2025-12-07
Unclassified MEDIUM 6.5
CVE-2025-13922

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'exi…

Mitigation only
Fix from $1,600 2025-12-06
Hibos HIGH 7.2
CVE-2025-14090

A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the file /manager/card/cardmake_dow…

No fix yet
Fix from $1,950 2025-12-05
Unclassified HIGH 7.3
CVE-2025-14091

A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555. This vulnerability affects unknown co…

Mitigation only
Fix from $1,950 2025-12-05
Unclassified HIGH 7.5
CVE-2025-12850

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.…

Mitigation only
Fix from $1,950 2025-12-05
Unclassified HIGH 7.5
CVE-2025-13373

Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL…

Mitigation only
Fix from $1,950 2025-12-04
Unclassified HIGH 8.7
CVE-2024-58276

Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers…

No fix yet
Fix from $1,950 2025-12-04
Unclassified HIGH 8.7
CVE-2023-53734

dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially …

No fix yet
Fix from $1,950 2025-12-04
Jizhicms HIGH 7.2
CVE-2025-14011

A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addcomment.html of the …

Fix: after 2.5.5
Fix from $1,950 2025-12-04
Jizhicms HIGH 7.2
CVE-2025-14012

A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/C…

Fix: after 2.5.5
Fix from $1,950 2025-12-04
Unclassified HIGH 8.6
CVE-2025-62173

## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API

Mitigation only
Fix from $1,950 2025-12-04
Taxopress MEDIUM 6.5
CVE-2025-13359

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsF…

Fix: 3.41.0+
Fix from $1,600 2025-12-03
Billing System MEDIUM 6.5
CVE-2025-65380

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidate…

Mitigation only
Fix from $1,600 2025-12-02
Billing System MEDIUM 6.5
CVE-2025-65379

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno pa…

Mitigation only
Fix from $1,600 2025-12-02
Lvzhou Cms HIGH 7.5
CVE-2025-65877

Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.…

Fix: 2025-09-22+
Fix from $1,950 2025-12-02
Online Medicine Guide CRITICAL 9.8
CVE-2025-60736

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

Mitigation only
Fix from $2,300 2025-12-02
Asyncmy CRITICAL 9.8
CVE-2025-65896

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

Fix: after 0.2.10
Fix from $2,300 2025-12-02
Edoc Doctor Appointment System CRITICAL 9.8
CVE-2025-65358

Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

Mitigation only
Fix from $2,300 2025-12-02
Gim CRITICAL 9.8
CVE-2025-41013

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete datab…

Fix: 2025-04-01+
Fix from $2,300 2025-12-02
Unclassified HIGH 8.6
CVE-2025-12465

A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesD…

Mitigation only
Fix from $1,950 2025-12-02
Unclassified HIGH 7.5
CVE-2025-13724

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all ver…

Mitigation only
Fix from $1,950 2025-12-02
Unclassified MEDIUM 6.5
CVE-2025-12483

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions…

Mitigation only
Fix from $1,600 2025-12-02
Db Access HIGH 7.7
CVE-2025-13000

The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to p…

Fix: after 0.8.7
Fix from $1,950 2025-12-02
Churchcrm HIGH 7.2
CVE-2025-66313

ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of th…

Fix: after 6.2.0
Fix from $1,950 2025-12-01
Frappe CRITICAL 9.8
CVE-2025-66205

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to…

Fix: 14.99.2 / 15.86.0+
Fix from $2,300 2025-12-01