Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-10218 A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/dao/SysRoleDao.go of the compo… Ruoyi Go Mitigation only Fix from $2,3002025-09-10 HIGH 8.8 CVE-2025-10210 A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Execu… Chancms after 3.3.0 Fix from $1,9502025-09-10 HIGH 8.8 CVE-2025-56407 A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/module… Utcms Mitigation only Fix from $1,9502025-09-10 CRITICAL 9.1 CVE-2025-9943 An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provide… Mitigation only Fix from $2,3002025-09-10 MEDIUM 6.5 CVE-2025-9463 The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL I… Mitigation only Fix from $1,6002025-09-10 MEDIUM 6.5 CVE-2025-7826 The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due… Mitigation only Fix from $1,6002025-09-10 MEDIUM 6.5 CVE-2025-6189 The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and in… Mitigation only Fix from $1,6002025-09-10 MEDIUM 6.3 CVE-2025-10197 A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality … No fix yet Fix from $1,6002025-09-10 CRITICAL 9.8 CVE-2025-58448 rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL … Rathena 2025-09-06+ Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-58462 OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attack… Foiaxpress Public Access Link 11.13.1.0+ Fix from $2,3002025-09-09 HIGH 7.6 CVE-2025-58993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.Th… Mitigation only Fix from $1,9502025-09-09 HIGH 7.6 CVE-2025-59008 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection z… Mitigation only Fix from $1,9502025-09-09 CRITICAL 9.3 CVE-2025-47569 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocomm… Mitigation only Fix from $2,3002025-09-09 MEDIUM 5.3 CVE-2025-10095 A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically affecting the handling of certa… Mitigation only Fix from $1,6002025-09-09 HIGH 7.2 CVE-2025-10122 A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing … Maccms Mitigation only Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-10118 A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unkno… E Logbook With Health Monitoring System For Covid 19 Mitigation only Fix from $2,3002025-09-09 MEDIUM 6.3 CVE-2025-10121 A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipulation of the argument note ca… Mitigation only Fix from $1,6002025-09-09 CRITICAL 9.8 CVE-2025-10114 A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulatio… Small Crm Mitigation only Fix from $2,3002025-09-09 HIGH 7.3 CVE-2025-10115 A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the arg… Mitigation only Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-10112 A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /ad… Student Information Management System Mitigation only Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-10113 A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /a… Student Information Management System Mitigation only Fix from $2,3002025-09-09 HIGH 8.2 CVE-2025-58453 WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /… Wegia 3.4.11+ Fix from $1,9502025-09-08 HIGH 8.2 CVE-2025-58454 WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /W… Wegia 3.4.11+ Fix from $1,9502025-09-08 CRITICAL 9.8 CVE-2025-10109 A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?actio… Online Loan Management System Mitigation only Fix from $2,3002025-09-08 HIGH 8.8 CVE-2025-10110 A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%2… Chancms after 3.3.1 Fix from $1,9502025-09-08 CRITICAL 9.8 CVE-2025-10111 A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the fil… Student Information Management System Mitigation only Fix from $2,3002025-09-08 CRITICAL 9.3 CVE-2025-58450 pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible in versions prior to 2.0.0-r… Patch available Fix from $2,3002025-09-08 CRITICAL 9.8 CVE-2025-10108 A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete… Online Loan Management System Mitigation only Fix from $2,3002025-09-08 HIGH 8.8 CVE-2025-10106 A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation o… Chancms after 3.3.1 Fix from $1,9502025-09-08 HIGH 8.8 CVE-2025-10105 A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This… Chancms after 3.3.1 Fix from $1,9502025-09-08