Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-51683 A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POS… Mjobtime Mitigation only Fix from $2,3002025-12-01 HIGH 8.8 CVE-2025-63535 A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize… Blood Bank Management System Mitigation only Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-63532 A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanit… Blood Bank Management System Mitigation only Fix from $1,9502025-12-01 CRITICAL 9.8 CVE-2025-63531 A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properl… Blood Bank Management System Mitigation only Fix from $2,3002025-12-01 HIGH 7.2 CVE-2025-13811 A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/… Webstack Guns No fix yet Fix from $1,9502025-12-01 CRITICAL 9.8 CVE-2025-13788 A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. Th… Chanjet Crm after 2025-11-06 Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13783 A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of… Wtcms after 2019-12-20 Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13782 A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the f… Wtcms after 2019-12-20 Fix from $2,3002025-11-30 MEDIUM 6.5 CVE-2025-13769 WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read databa… Webitr 2_1_0_34+ Fix from $1,6002025-11-28 MEDIUM 6.5 CVE-2025-13770 WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read databa… Webitr 2_1_0_34+ Fix from $1,6002025-11-28 HIGH 8.8 CVE-2025-13757 SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8. Devolutions Server 2025.2.21.0 / 2025.3.10.0+ Fix from $1,9502025-11-27 HIGH 8.8 CVE-2025-11461 Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. Thi… Frappe Crm Patch available Fix from $1,9502025-11-26 CRITICAL 9.8 CVE-2025-65236 OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpan… Ussd Gateway Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-65235 OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSu… Ussd Gateway Mitigation only Fix from $2,3002025-11-26 MEDIUM 5.4 CVE-2025-62728 SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i… Hive Mitigation only Fix from $1,6002025-11-26 MEDIUM 6.5 CVE-2025-66260 PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000… Mozart Next 100 Firmware No fix yet Fix from $1,6002025-11-26 MEDIUM 6.5 CVE-2025-61167 SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas… Pmb Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.9 CVE-2025-59369 A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute… Mitigation only Fix from $1,6002025-11-25 MEDIUM 6.5 CVE-2025-10144 The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortc… Mitigation only Fix from $1,6002025-11-24 HIGH 7.6 CVE-2025-56401 ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName. Wbrm No fix yet Fix from $1,9502025-11-24 HIGH 7.2 CVE-2025-13586 A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. T… Online Student Clearance System No fix yet Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-13585 A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipu… Covid Tracking System Mitigation only Fix from $2,3002025-11-24 HIGH 7.5 CVE-2025-7402 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘site_id’ par… Mitigation only Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-13583 A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the compo… Question Paper Generator Mitigation only Fix from $2,3002025-11-24 HIGH 8.8 CVE-2025-13581 A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file… Student Information System No fix yet Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-13582 A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functionality of the file /detail.php … Jonnys Liquor Mitigation only Fix from $2,3002025-11-24 CRITICAL 9.8 CVE-2025-13578 A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. T… Library System Mitigation only Fix from $2,3002025-11-24 HIGH 8.8 CVE-2025-13579 A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argu… Library System No fix yet Fix from $1,9502025-11-24 HIGH 8.8 CVE-2025-13580 A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.php. This manipulation of the a… Library System No fix yet Fix from $1,9502025-11-24 HIGH 8.8 CVE-2025-13575 A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/… Blog Site Mitigation only Fix from $1,9502025-11-24