Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2025-53727 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6465.1 / 13.0.7060.1+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-49759 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6465.1 / 13.0.7060.1+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-47954 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2022 16.0.1145.1 / 16.0.4210.1+ Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-55167 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vuln… Wegia 3.4.8+ Fix from $2,3002025-08-12 HIGH 7.2 CVE-2025-8296 SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL que… Avalanche 6.4.8.8008+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-55156 pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_… Patch available Fix from $1,9502025-08-11 CRITICAL 9.8 CVE-2024-32640EPSS 70% MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injec… Patch available Fix from $2,3002025-08-11 CRITICAL 9.8 CVE-2025-8811 A vulnerability, which was classified as critical, has been found in code-projects Simple Art Gallery 1.0. Affected by this issue is some unknown fun… Simple Art Gallery Mitigation only Fix from $2,3002025-08-10 CRITICAL 9.8 CVE-2025-8809 A vulnerability classified as critical has been found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /addeli… Online Medicine Guide Mitigation only Fix from $2,3002025-08-10 CRITICAL 9.8 CVE-2025-8806 A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been classified as crit… Adp Application Developer Platform Mitigation only Fix from $2,3002025-08-10 CRITICAL 9.8 CVE-2025-8773 A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown functi… Monitoring Platform Mitigation only Fix from $2,3002025-08-09 HIGH 7.3 CVE-2025-8744 A vulnerability classified as critical was found in CesiumLab Web up to 4.0. This vulnerability affects unknown code of the file /lodmodels/. The man… Mitigation only Fix from $1,9502025-08-09 CRITICAL 10.0 CVE-2012-10047 Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth… Mitigation only Fix from $2,3002025-08-08 HIGH 8.8 CVE-2025-52914 A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacke… Micollab 9.8.3.103 / 10.1.0.10+ Fix from $1,9502025-08-08 MEDIUM 6.5 CVE-2025-50467 OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio… Openmetadata after 1.4.4 Fix from $1,6002025-08-08 MEDIUM 6.5 CVE-2025-50468 OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO i… Openmetadata after 1.4.4 Fix from $1,6002025-08-08 HIGH 8.8 CVE-2025-50465 OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio… Openmetadata after 1.4.4 Fix from $1,9502025-08-08 MEDIUM 6.5 CVE-2025-50466 OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio… Openmetadata after 1.4.4 Fix from $1,6002025-08-08 HIGH 8.8 CVE-2025-8706 A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnera… Woes Intelligent Optimization Energy Saving System No fix yet Fix from $1,9502025-08-08 HIGH 8.8 CVE-2025-8703 A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknow… Woes Intelligent Optimization Energy Saving System No fix yet Fix from $1,9502025-08-08 HIGH 8.8 CVE-2025-8704 A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affec… Woes Intelligent Optimization Energy Saving System No fix yet Fix from $1,9502025-08-08 HIGH 8.8 CVE-2025-8705 A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknow… Woes Intelligent Optimization Energy Saving System No fix yet Fix from $1,9502025-08-08 HIGH 8.8 CVE-2025-8702 A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part… Woes Intelligent Optimization Energy Saving System No fix yet Fix from $1,9502025-08-08 HIGH 8.8 CVE-2025-8701 A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is… Woes Intelligent Optimization Energy Saving System No fix yet Fix from $1,9502025-08-07 CRITICAL 9.8 CVE-2023-41525 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. Hospital Management System Mitigation only Fix from $2,3002025-08-07 CRITICAL 9.8 CVE-2023-41526 Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameter… Hospital Management System Mitigation only Fix from $2,3002025-08-07 CRITICAL 9.8 CVE-2023-41527 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. Hospital Management System Mitigation only Fix from $2,3002025-08-07 CRITICAL 9.8 CVE-2023-41528 Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail … Hospital Management System Mitigation only Fix from $2,3002025-08-07 CRITICAL 9.8 CVE-2023-41530 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. Hospital Management System Mitigation only Fix from $2,3002025-08-07 HIGH 8.8 CVE-2023-41531 Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameter… Hospital Management System Mitigation only Fix from $1,9502025-08-07