Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2025-49931 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSearch jet-search allows Blind SQ… Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.3 CVE-2025-49915 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-a… Mitigation only Fix from $2,3002025-10-22 HIGH 8.5 CVE-2025-49378 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL… Mitigation only Fix from $1,9502025-10-22 HIGH 8.5 CVE-2025-48091 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Inje… Mitigation only Fix from $1,9502025-10-22 MEDIUM 6.5 CVE-2025-61194 daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php. Daicuo No fix yet Fix from $1,6002025-10-21 MEDIUM 6.5 CVE-2025-56450 Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLead… Mitigation only Fix from $1,6002025-10-21 HIGH 7.1 CVE-2025-9339 SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injecti… Mitigation only Fix from $1,9502025-10-21 HIGH 8.8 CVE-2025-9428EPSS 26% Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. Manageengine Analytics Plus 6.1+ Fix from $1,9502025-10-21 MEDIUM 6.5 CVE-2025-60783 There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipul… Restaurant Management System Dbms Project No fix yet Fix from $1,6002025-10-20 HIGH 7.5 CVE-2025-62658 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalyti… Mitigation only Fix from $1,9502025-10-20 HIGH 8.8 CVE-2025-47902 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injecti… Timeprovider 4100 Firmware 2.5+ Fix from $1,9502025-10-20 CRITICAL 9.8 CVE-2025-61455 SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorpo… Mitigation only Fix from $2,3002025-10-20 CRITICAL 9.3 CVE-2025-41028 A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and d… Mitigation only Fix from $2,3002025-10-20 HIGH 7.2 CVE-2025-11944 A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the c… Vvveb after 1.0.7.3 Fix from $1,9502025-10-19 HIGH 7.5 CVE-2025-11691 The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() f… Mitigation only Fix from $1,9502025-10-18 HIGH 8.8 CVE-2025-11911 A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Actio… Streamax Crocus No fix yet Fix from $1,9502025-10-17 HIGH 8.8 CVE-2025-11912 A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query.… Streamax Crocus No fix yet Fix from $1,9502025-10-17 HIGH 8.8 CVE-2025-11910 A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /Memory… Streamax Crocus No fix yet Fix from $1,9502025-10-17 HIGH 8.8 CVE-2025-11909 A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /Rep… Streamax Crocus No fix yet Fix from $1,9502025-10-17 CRITICAL 9.8 CVE-2025-56316 A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbit… Mcms Mitigation only Fix from $2,3002025-10-17 MEDIUM 6.5 CVE-2025-60514 Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts. Patch available Fix from $1,6002025-10-17 HIGH 8.8 CVE-2025-62422 DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface i… Dataease 2.10.14+ Fix from $1,9502025-10-17 HIGH 7.2 CVE-2025-11904 A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation … Chancms after 3.3.2 Fix from $1,9502025-10-17 HIGH 7.2 CVE-2025-11903 A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a… Chancms after 3.3.2 Fix from $1,9502025-10-17 HIGH 7.2 CVE-2025-11902 A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/f… Chancms after 3.3.2 Fix from $1,9502025-10-17 HIGH 7.2 CVE-2025-62423 ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admi… Clipbucket 5.5.2-142+ Fix from $1,9502025-10-16 MEDIUM 6.5 CVE-2025-60641 The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel']… Mitigation only Fix from $1,6002025-10-16 MEDIUM 5.4 CVE-2025-56699 SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to e… Mitigation only Fix from $1,6002025-10-16 MEDIUM 5.4 CVE-2025-56700 Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged use… Mitigation only Fix from $1,6002025-10-16 MEDIUM 6.5 CVE-2025-61540 SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. Ultimate Php Board Mitigation only Fix from $1,6002025-10-16