Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.5 CVE-2025-63878 Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page. Restaurant Website Restoran No fix yet Fix from $1,6002025-11-19 HIGH 7.2 CVE-2025-65022 i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exis… I Educar after 2.10.0 Fix from $1,9502025-11-19 HIGH 7.2 CVE-2025-65023 i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exis… I Educar after 2.10.0 Fix from $1,9502025-11-19 HIGH 7.2 CVE-2025-65024 i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exis… I Educar after 2.10.0 Fix from $1,9502025-11-19 CRITICAL 9.8 CVE-2025-13396 A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This man… Courier Management System Mitigation only Fix from $2,3002025-11-19 CRITICAL 9.8 CVE-2025-10437 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer In… Mitigation only Fix from $2,3002025-11-19 HIGH 7.3 CVE-2025-13395 A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted element is the function Login o… Mitigation only Fix from $1,9502025-11-19 HIGH 7.5 CVE-2025-12646 The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 du… Mitigation only Fix from $1,9502025-11-19 MEDIUM 5.5 CVE-2025-65093 LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerabi… Librenms 25.11.0+ Fix from $1,6002025-11-18 CRITICAL 9.8 CVE-2025-63694 DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage. Dzzoffice after 2.3.7 Fix from $2,3002025-11-18 MEDIUM 6.5 CVE-2025-63512 kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The applicat… Hospital Management System No fix yet Fix from $1,6002025-11-18 HIGH 8.8 CVE-2025-58692 An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7… Fortivoice 7.0.8 / 7.2.3+ Fix from $1,9502025-11-18 MEDIUM 5.3 CVE-2025-9977 Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an… Mitigation only Fix from $1,6002025-11-18 HIGH 8.8 CVE-2025-13347 A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save… Train Station Ticketing System No fix yet Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-13346 A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_sta… Train Station Ticketing System No fix yet Fix from $1,9502025-11-18 CRITICAL 9.8 CVE-2025-13344 A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of th… Train Station Ticketing System Mitigation only Fix from $2,3002025-11-18 HIGH 8.8 CVE-2025-13345 A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality… Train Station Ticketing System No fix yet Fix from $1,9502025-11-18 CRITICAL 9.8 CVE-2025-41348 SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete dat… Winplus Mitigation only Fix from $2,3002025-11-18 HIGH 7.1 CVE-2025-12411 The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' parameter in versions up to, and inc… No fix yet Fix from $1,9502025-11-18 CRITICAL 9.8 CVE-2025-13323 A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Pe… Simple Pizza Ordering System Mitigation only Fix from $2,3002025-11-18 HIGH 8.8 CVE-2025-13325 A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_ed… Student Information System No fix yet Fix from $1,9502025-11-18 CRITICAL 9.8 CVE-2025-13302 A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such ma… Courier Management System Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2025-13303 A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /sear… Courier Management System Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2025-13300 A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /sett… Web Based Internet Laboratory Management System Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2025-13301 A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functiona… Web Based Internet Laboratory Management System Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2025-13298 A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrol… Web Based Internet Laboratory Management System Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2025-13299 A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/control… Web Based Internet Laboratory Management System Mitigation only Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2024-44659 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. Online Shopping Portal Mitigation only Fix from $2,3002025-11-17 MEDIUM 6.5 CVE-2024-44664 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-d… Online Shopping Portal No fix yet Fix from $1,6002025-11-17 MEDIUM 6.5 CVE-2024-44660 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. Online Shopping Portal No fix yet Fix from $1,6002025-11-17