Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.1 CVE-2024-32323 SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information via the if parameter in hcit.p… Mitigation only Fix from $1,9502025-07-17 CRITICAL 9.8 CVE-2025-25257 KEVEPSS 100% An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6… Fortiweb 7.0.11 / 7.2.11+ Fix from $2,3002025-07-17 HIGH 8.8 CVE-2025-54058 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified… Wegia 3.4.6+ Fix from $1,9502025-07-17 HIGH 8.8 CVE-2025-54060 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified… Wegia 3.4.6+ Fix from $1,9502025-07-17 HIGH 8.8 CVE-2025-54061 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified… Wegia 3.4.6+ Fix from $1,9502025-07-17 HIGH 8.8 CVE-2025-54062 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified… Wegia 3.4.6+ Fix from $1,9502025-07-17 HIGH 8.8 CVE-2025-53946 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified… Wegia 3.4.5+ Fix from $1,9502025-07-17 HIGH 7.5 CVE-2025-7735 The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary … Mitigation only Fix from $1,9502025-07-17 CRITICAL 9.8 CVE-2025-53937 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified… Wegia 3.4.5+ Fix from $2,3002025-07-16 HIGH 7.1 CVE-2025-37104 A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to pe… Mitigation only Fix from $1,9502025-07-16 HIGH 8.5 CVE-2025-52819 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Envíos pakke allows SQL Injection… Mitigation only Fix from $1,9502025-07-16 HIGH 8.5 CVE-2025-49876 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profile… Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.3 CVE-2025-52714 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows SQL Injecti… Mitigation only Fix from $2,3002025-07-16 HIGH 7.6 CVE-2025-49034 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder… Mitigation only Fix from $1,9502025-07-16 HIGH 8.5 CVE-2025-32574 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection. This issue… Mitigation only Fix from $1,9502025-07-16 HIGH 8.5 CVE-2025-47645 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edi… Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.8 CVE-2025-28982 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This i… Wp Pipes after 1.4.3 Fix from $2,3002025-07-16 CRITICAL 9.3 CVE-2025-30936 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod … Mitigation only Fix from $2,3002025-07-16 CRITICAL 9.3 CVE-2025-24759 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugin… Mitigation only Fix from $2,3002025-07-16 CRITICAL 9.3 CVE-2025-28959 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener exact-links a… Mitigation only Fix from $2,3002025-07-16 HIGH 7.6 CVE-2025-54043 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES smtp-amazon-ses… Mitigation only Fix from $1,9502025-07-16 HIGH 8.5 CVE-2025-54026 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes gymbase_clas… Mitigation only Fix from $1,9502025-07-16 HIGH 7.6 CVE-2025-48299 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra yayextra allows SQL Inject… Mitigation only Fix from $1,9502025-07-16 HIGH 7.6 CVE-2025-48301 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP smtp-se… Mitigation only Fix from $1,9502025-07-16 HIGH 7.6 CVE-2025-48161 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP smtp-sendinblue allows SQL … Mitigation only Fix from $1,9502025-07-16 HIGH 8.3 CVE-2025-40985 SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data … Mitigation only Fix from $1,9502025-07-16 HIGH 8.1 CVE-2025-26186 SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php Opensis Patch available Fix from $1,9502025-07-15 CRITICAL 10.0 CVE-2025-34112 An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances… Mitigation only Fix from $2,3002025-07-15 HIGH 8.8 CVE-2025-53823 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection… Wegia 3.4.5+ Fix from $1,9502025-07-14 CRITICAL 9.8 CVE-2025-53639 MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not proper… Metersphere 3.6.5+ Fix from $2,3002025-07-14