Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2025-41019 SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' p… Mitigation only Fix from $2,3002025-10-16 CRITICAL 9.8 CVE-2025-41018 SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' pa… Exito Mitigation only Fix from $2,3002025-10-16 HIGH 7.5 CVE-2025-11177 The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, and including, 1.11.2 due to in… Mitigation only Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-11365 The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versio… Mitigation only Fix from $1,6002025-10-15 MEDIUM 6.5 CVE-2025-10660 The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.0.3 due to i… Mitigation only Fix from $1,6002025-10-15 MEDIUM 6.5 CVE-2025-10682 The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to insufficient neutralization o… Mitigation only Fix from $1,6002025-10-15 MEDIUM 6.5 CVE-2025-10730 The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all versions up to, and including, 4… Mitigation only Fix from $1,6002025-10-15 HIGH 7.5 CVE-2025-10743 The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and including, 1.3.2 due to insufficient… Mitigation only Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-10575 The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter handled by the WPJqueryPaged::get… Mitigation only Fix from $1,6002025-10-15 HIGH 7.5 CVE-2025-11501 The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all versions up to, and including,… Mitigation only Fix from $1,9502025-10-15 HIGH 8.6 CVE-2025-61675EPSS 39% FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions pr… Mitigation only Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-11736 A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Thi… Online Examination System Mitigation only Fix from $2,3002025-10-14 HIGH 8.8 CVE-2025-59213 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attack… Configuration Manager 2403 5.00.9128.1035 / 5.00.9132.1029+ Fix from $1,9502025-10-14 MEDIUM 6.8 CVE-2025-55320 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker… Configuration Manager 2403 5.00.9128.1035 / 5.00.9132.1029+ Fix from $1,6002025-10-14 CRITICAL 9.8 CVE-2025-10610 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry … Mitigation only Fix from $2,3002025-10-14 HIGH 8.8 CVE-2025-40755 A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAnd… Sinec Nms 4.0+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-62388 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62389 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62390 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62391 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62392 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62383 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62384 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62385 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62386 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62387 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 HIGH 8.8 CVE-2025-62360 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was iden… Wegia 3.5.1+ Fix from $1,9502025-10-13 MEDIUM 6.5 CVE-2025-11623 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 HIGH 8.8 CVE-2025-62177 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was ide… Wegia 3.5.1+ Fix from $1,9502025-10-13 HIGH 8.8 CVE-2025-62179 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was ide… Wegia 3.5.1+ Fix from $1,9502025-10-13