Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2025-12261 A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/actions/remove-announcement.php… Gym Management System No fix yet Fix from $1,9502025-10-27 CRITICAL 9.8 CVE-2025-12257 A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file… Online Student Result System Mitigation only Fix from $2,3002025-10-27 HIGH 8.8 CVE-2025-12256 A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /edit_contestant… Online Event Judging System No fix yet Fix from $1,9502025-10-27 CRITICAL 9.8 CVE-2025-12253 A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /… Hibos Mitigation only Fix from $2,3002025-10-27 HIGH 8.8 CVE-2025-12254 A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown functionality of the file /ad… Online Event Judging System No fix yet Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12255 A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of the file /add_contestant.php. P… Online Event Judging System No fix yet Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12252 A vulnerability was found in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /ajax/action.php. The manipul… Online Event Judging System No fix yet Fix from $1,9502025-10-27 HIGH 7.3 CVE-2025-12248 A security vulnerability has been detected in CLTPHP 3.0. The affected element is an unknown function of the file /home/search.html. Such manipulatio… Mitigation only Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12242 A vulnerability has been found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/… Gym Management System No fix yet Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12243 A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/… Client Details System No fix yet Fix from $1,9502025-10-27 CRITICAL 9.8 CVE-2025-12237 A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /index.php. Such … Advanced Library Management System Mitigation only Fix from $2,3002025-10-27 HIGH 8.8 CVE-2025-12238 A security flaw has been discovered in code-projects Automated Voting System 1.0. The affected element is an unknown function of the file /admin/user… Automated Voting System No fix yet Fix from $1,9502025-10-27 CRITICAL 9.8 CVE-2025-12226 A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php… Best House Rental Management System Mitigation only Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-12215 A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_submit.php. Executing a manipul… Online Shopping System Mitigation only Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-12208 A vulnerability was found in SourceCodester Best House Rental Management System 1.0. This impacts the function login2 of the file /admin_class.php. P… Best House Rental Management System Mitigation only Fix from $2,3002025-10-27 HIGH 7.3 CVE-2025-8709 A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affec… Mitigation only Fix from $1,9502025-10-26 HIGH 7.5 CVE-2025-4203 The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, … Mitigation only Fix from $1,9502025-10-25 HIGH 7.5 CVE-2025-8416 The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in all versions up to, and inclu… Mitigation only Fix from $1,9502025-10-25 HIGH 7.5 CVE-2025-9322 The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to SQL Injection … Mitigation only Fix from $1,9502025-10-25 MEDIUM 6.5 CVE-2025-11893 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via … Mitigation only Fix from $1,6002025-10-25 CRITICAL 9.3 CVE-2025-8536 A SQL injection vulnerability has been identified in DobryCMS. Improper neutralization of input provided by user into language functionality allows f… Mitigation only Fix from $2,3002025-10-24 CRITICAL 9.8 CVE-2025-11253 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology Inc. Netty ERP allows SQL Inje… Mitigation only Fix from $2,3002025-10-24 MEDIUM 6.3 CVE-2025-10740 The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missin… Mitigation only Fix from $1,6002025-10-24 MEDIUM 6.5 CVE-2025-10748 The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and including, 1.2. This is due to i… Mitigation only Fix from $1,6002025-10-24 MEDIUM 6.5 CVE-2025-61464 gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. Gnuboard after 4.36.04 Fix from $1,6002025-10-23 HIGH 7.2 CVE-2025-62617 Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assign… Admidio 4.3.17+ Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-62606 my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authentica… Mitigation only Fix from $1,9502025-10-22 HIGH 7.6 CVE-2025-62015 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce … Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.3 CVE-2025-59557 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQ… Mitigation only Fix from $2,3002025-10-22 CRITICAL 10.0 CVE-2025-57870 A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a… Arcgis Server after 11.5 Fix from $2,3002025-10-22