Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-59743 SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases b… E Tms Mitigation only Fix from $2,3002025-10-02 MEDIUM 6.5 CVE-2025-56380 Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endp… Erpnext No fix yet Fix from $1,6002025-10-02 MEDIUM 6.5 CVE-2025-56381 ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orde… Erpnext No fix yet Fix from $1,6002025-10-02 HIGH 8.8 CVE-2025-11020 An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of… Mitigation only Fix from $1,9502025-10-02 CRITICAL 9.8 CVE-2025-59681 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega… Django 4.2.25 / 5.1.13+ Fix from $2,3002025-10-01 HIGH 8.2 CVE-2025-52040 In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attack… Erpnext Patch available Fix from $1,9502025-10-01 HIGH 8.2 CVE-2025-52041 In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable t… Erpnext Patch available Fix from $1,9502025-10-01 HIGH 8.2 CVE-2025-52042 In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vul… Erpnext Patch available Fix from $1,9502025-10-01 HIGH 8.2 CVE-2025-52039 In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vu… Erpnext Patch available Fix from $1,9502025-10-01 MEDIUM 6.5 CVE-2025-57254 An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execut… Mitigation only Fix from $1,6002025-09-30 MEDIUM 6.5 CVE-2025-52043 In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnera… Erpnext Patch available Fix from $1,6002025-09-30 MEDIUM 6.5 CVE-2025-52047 In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attac… Erpnext Patch available Fix from $1,6002025-09-30 MEDIUM 6.5 CVE-2025-52049 In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injectio… Erpnext Patch available Fix from $1,6002025-09-30 MEDIUM 6.5 CVE-2025-52050 In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is v… Erpnext Patch available Fix from $1,6002025-09-30 HIGH 7.5 CVE-2025-8877 The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and incl… Mitigation only Fix from $1,9502025-09-30 HIGH 8.8 CVE-2025-8122 Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss… Pad Cms after 1.2.1 Fix from $1,9502025-09-30 HIGH 8.8 CVE-2025-8121 Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss… Pad Cms after 1.2.1 Fix from $1,9502025-09-30 CRITICAL 9.8 CVE-2024-13150 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.… No fix yet Fix from $2,3002025-09-29 HIGH 8.8 CVE-2025-8868EPSS 23% In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict… Automate 4.13.295+ Fix from $1,9502025-09-29 HIGH 8.8 CVE-2025-6724 In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict… Automate 4.13.295+ Fix from $1,9502025-09-29 CRITICAL 9.8 CVE-2025-11118 A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such … Student Grading System Mitigation only Fix from $2,3002025-09-28 CRITICAL 9.8 CVE-2025-11116 A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of … Simple Scheduling System Mitigation only Fix from $2,3002025-09-28 CRITICAL 9.8 CVE-2025-11115 A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown functionality of the file /addti… Simple Scheduling System Mitigation only Fix from $2,3002025-09-28 HIGH 8.8 CVE-2025-11113 A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulat… Online Leave Application No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11114 A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicat… Online Leave Application No fix yet Fix from $1,9502025-09-28 CRITICAL 9.8 CVE-2025-11111 A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/candida… Advanced Online Voting System Mitigation only Fix from $2,3002025-09-28 CRITICAL 9.8 CVE-2025-11110 A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admi… Online Learning Management System Mitigation only Fix from $2,3002025-09-28 CRITICAL 9.8 CVE-2025-11109 A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/u… Computer Sales And Inventory System Mitigation only Fix from $2,3002025-09-28 CRITICAL 9.8 CVE-2025-11108 A vulnerability was determined in code-projects Simple Scheduling System 1.0. Impacted is an unknown function of the file /schedulingsystem/addroom.p… Simple Scheduling System Mitigation only Fix from $2,3002025-09-28 CRITICAL 9.8 CVE-2025-11107 A vulnerability was found in code-projects Simple Scheduling System 1.0. This issue affects some unknown processing of the file /schedulingsystem/add… Simple Scheduling System Mitigation only Fix from $2,3002025-09-28