Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-3998 A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file r… Membership Management System No fix yet Fix from $2,3002025-04-28 CRITICAL 9.8 CVE-2025-3976 A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of… Covid19 Testing Management System Mitigation only Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3973 A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the… Covid19 Testing Management System Mitigation only Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3974 A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown cod… Covid19 Testing Management System Mitigation only Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3972 A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some… Covid19 Testing Management System Mitigation only Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3971 A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown fu… Covid19 Testing Management System Mitigation only Fix from $2,3002025-04-27 HIGH 8.8 CVE-2025-3968 A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown co… News Publishing Site Dashboard No fix yet Fix from $1,9502025-04-27 CRITICAL 9.8 CVE-2025-3957 A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main… Springboot Admin No fix yet Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3956 A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the function RestResp of the fil… Novel Cloud Mitigation only Fix from $2,3002025-04-27 HIGH 7.5 CVE-2025-46578 There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject com… Zxcloud Goldendb 6.1.03.11+ Fix from $1,9502025-04-27 HIGH 7.5 CVE-2025-46577 There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information. Zxcloud Goldendb 6.1.03.11+ Fix from $1,9502025-04-27 HIGH 7.5 CVE-2025-3955 A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of th… Patient Record Management System No fix yet Fix from $1,9502025-04-27 CRITICAL 9.8 CVE-2025-25775 Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder. Bus Ticket Booking System No fix yet Fix from $2,3002025-04-25 MEDIUM 6.5 CVE-2025-28076 Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary … Mitigation only Fix from $1,6002025-04-25 HIGH 8.8 CVE-2025-46546 In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /… Sherpa Orchestrator Mitigation only Fix from $1,9502025-04-25 MEDIUM 6.5 CVE-2025-29529 ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.as… Patch available Fix from $1,6002025-04-24 CRITICAL 9.3 CVE-2025-46248 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-da… Mitigation only Fix from $2,3002025-04-24 HIGH 8.5 CVE-2025-39377 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper appsero-helper allows SQL… Mitigation only Fix from $1,9502025-04-24 MEDIUM 6.5 CVE-2025-44134 A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of … Online Class And Exam Scheduling System No fix yet Fix from $1,6002025-04-24 MEDIUM 6.5 CVE-2025-44135 A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the para… Online Class And Exam Scheduling System No fix yet Fix from $1,6002025-04-24 HIGH 7.2 CVE-2025-3872 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form … Centreon Web 22.10.28 / 23.04.25+ Fix from $1,9502025-04-24 MEDIUM 6.5 CVE-2025-3280 The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_fi… Mitigation only Fix from $1,6002025-04-24 HIGH 8.0 CVE-2025-1520 PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute… Posthog 0.3.7+ Fix from $1,9502025-04-23 HIGH 8.8 CVE-2025-32968 XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with S… Xwiki 15.10.16 / 16.4.6+ Fix from $1,9502025-04-23 CRITICAL 9.8 CVE-2025-32969EPSS 78% XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticat… Xwiki 15.10.16 / 16.4.6+ Fix from $2,3002025-04-23 CRITICAL 9.8 CVE-2025-43949 MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statem… Mitigation only Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2023-44755 Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php. Sacco Management System No fix yet Fix from $2,3002025-04-22 HIGH 7.2 CVE-2025-3767 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allo… Mitigation only Fix from $1,9502025-04-22 HIGH 8.8 CVE-2025-23176 CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') No fix yet Fix from $1,9502025-04-22 HIGH 7.2 CVE-2025-46252 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 c… Message Filter For Contact Form 7 1.6.3.3+ Fix from $1,9502025-04-22