Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-57819 KEVEPSS 88% FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-su… Freepbx 15.0.66 / 16.0.89+ Fix from $2,3002025-08-28 MEDIUM 6.5 CVE-2025-51972 A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supp… Online Shopping System Advanced No fix yet Fix from $1,6002025-08-28 MEDIUM 5.4 CVE-2025-51971 A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user i… Online Shopping System Advanced No fix yet Fix from $1,6002025-08-28 MEDIUM 6.5 CVE-2025-51969 A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the produ… Online Shopping System Advanced No fix yet Fix from $1,6002025-08-28 MEDIUM 6.5 CVE-2025-51968 A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly … Online Shopping System Advanced No fix yet Fix from $1,6002025-08-28 CRITICAL 9.3 CVE-2025-54720 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL … Mitigation only Fix from $2,3002025-08-28 HIGH 8.5 CVE-2025-49402 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scriptsbundle Exertio Framework exertio-framewo… Mitigation only Fix from $1,9502025-08-28 HIGH 8.5 CVE-2025-49404 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in purethemes Listeo Core listeo-core allows SQL I… Mitigation only Fix from $1,9502025-08-28 CRITICAL 9.3 CVE-2025-39496 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Inje… Mitigation only Fix from $2,3002025-08-28 MEDIUM 6.5 CVE-2025-8977 The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and includi… Mitigation only Fix from $1,6002025-08-28 CRITICAL 9.3 CVE-2025-34162 An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control Sy… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2024-13979 A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL … St. Joe Erp System Mitigation only Fix from $2,3002025-08-27 HIGH 7.0 CVE-2025-51667 An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-core system has a limited SQL… Simple Admin after 1.6.7 Fix from $1,9502025-08-27 HIGH 8.6 CVE-2025-50979EPSS 8% NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro… Nodebb No fix yet Fix from $1,9502025-08-27 MEDIUM 5.3 CVE-2025-50984 diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsa… Diskover No fix yet Fix from $1,6002025-08-27 HIGH 8.3 CVE-2025-50983 SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails … Readarr No fix yet Fix from $1,9502025-08-27 CRITICAL 9.8 CVE-2025-50972 SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to inde… Abantecart Mitigation only Fix from $2,3002025-08-27 HIGH 8.8 CVE-2025-9531 A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Ag… I Educar after 2.10 Fix from $1,9502025-08-27 HIGH 8.8 CVE-2025-9532 A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/view. Executing manipulation of… I Educar after 2.10 Fix from $1,9502025-08-27 MEDIUM 6.9 CVE-2025-30061 In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parameter. Mitigation only Fix from $1,6002025-08-27 MEDIUM 6.9 CVE-2025-30059 In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. Mitigation only Fix from $1,6002025-08-27 MEDIUM 6.9 CVE-2025-30060 In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" parameter. Mitigation only Fix from $1,6002025-08-27 MEDIUM 6.9 CVE-2025-30058 In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter. Mitigation only Fix from $1,6002025-08-27 CRITICAL 9.8 CVE-2025-9511 A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /visitor/addvisit… Apartment Management System Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-9508 A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /report/rented_… Apartment Management System Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-9509 A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/f… Apartment Management System Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-9510 A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /… Apartment Management System Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-9507 A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/visitor_info.php.… Apartment Management System Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-9506 A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_plan.… Online Loan Management System Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-9505 A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?acti… Online Loan Management System Mitigation only Fix from $2,3002025-08-27