Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.0 CVE-2025-63724 SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php. Svx Portal No fix yet Fix from $1,6002025-11-14 HIGH 8.8 CVE-2025-13171 A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument… Zzcms No fix yet Fix from $1,9502025-11-14 HIGH 8.8 CVE-2025-13172 A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php… Gym Management System Mitigation only Fix from $1,9502025-11-14 CRITICAL 9.8 CVE-2025-13169 A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of th… Simple Online Hotel Reservation System Mitigation only Fix from $2,3002025-11-14 CRITICAL 9.8 CVE-2025-13170 A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /adm… Simple Online Hotel Reservation System Mitigation only Fix from $2,3002025-11-14 MEDIUM 6.5 CVE-2024-44636 PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php. Student Record System Mitigation only Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2024-44639 PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php. Student Record System No fix yet Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2024-44640 PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php. Student Record System No fix yet Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2024-55016 PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php. Student Record System No fix yet Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2024-44630 Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lna… Student Record System No fix yet Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2024-44632 PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php. Student Record System No fix yet Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2024-44633 PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php. Student Record System No fix yet Fix from $1,6002025-11-14 CRITICAL 9.8 CVE-2025-13168 A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py.… Ury 0.2.1+ Fix from $2,3002025-11-14 HIGH 8.7 CVE-2022-4984 ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerabi… Mitigation only Fix from $1,9502025-11-13 CRITICAL 9.8 CVE-2025-13123 A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdat… Hibos Mitigation only Fix from $2,3002025-11-13 CRITICAL 9.8 CVE-2025-13122 A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppo… Patients Waiting Area Queue Management System Mitigation only Fix from $2,3002025-11-13 HIGH 7.3 CVE-2025-13121 A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/Sto… Mitigation only Fix from $1,9502025-11-13 CRITICAL 9.8 CVE-2025-13075 A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Perfo… Responsive Hotel Site Mitigation only Fix from $2,3002025-11-12 CRITICAL 9.8 CVE-2025-13076 A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Exe… Responsive Hotel Site Mitigation only Fix from $2,3002025-11-12 CRITICAL 9.8 CVE-2025-13059 A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career… Alumni Management System Mitigation only Fix from $2,3002025-11-12 CRITICAL 9.8 CVE-2025-13060 A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey… Survey Application System Mitigation only Fix from $2,3002025-11-12 CRITICAL 9.8 CVE-2025-56385 A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-suppl… Harmony Mitigation only Fix from $2,3002025-11-12 CRITICAL 9.8 CVE-2025-13057 A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=s… School Fees Payment Management System Mitigation only Fix from $2,3002025-11-12 HIGH 7.6 CVE-2025-64293 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Analytics 0-day-analytics allows … Mitigation only Fix from $1,9502025-11-12 CRITICAL 9.8 CVE-2025-64280 A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field. Community Development Mitigation only Fix from $2,3002025-11-12 MEDIUM 6.5 CVE-2025-11454 The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_s… Mitigation only Fix from $1,6002025-11-12 HIGH 8.8 CVE-2025-59499 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6475.1 / 13.0.7070.1+ Fix from $1,9502025-11-11 CRITICAL 9.8 CVE-2025-8324 Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration. Mitigation only Fix from $2,3002025-11-11 MEDIUM 5.4 CVE-2025-42889 SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this … Mitigation only Fix from $1,6002025-11-11 HIGH 8.8 CVE-2025-64519 TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL i… Torrentpier after 2.8.8 Fix from $1,9502025-11-10