Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-3856 A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/s… Novel Plus No fix yet Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-3847 A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httpreq… Webserver Mitigation only Fix from $2,3002025-04-21 CRITICAL 9.8 CVE-2025-3846 A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of… Webserver Mitigation only Fix from $2,3002025-04-21 HIGH 8.0 CVE-2025-32956 ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a n… Managewiki 2025-04-20+ Fix from $1,9502025-04-21 CRITICAL 9.8 CVE-2025-3828 A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the… Men Salon Management System No fix yet Fix from $2,3002025-04-20 CRITICAL 9.8 CVE-2025-3829 A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the f… Men Salon Management System No fix yet Fix from $2,3002025-04-20 CRITICAL 9.8 CVE-2025-3827 A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of t… Men Salon Management System No fix yet Fix from $2,3002025-04-20 MEDIUM 6.3 CVE-2025-3818 A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the f… Mitigation only Fix from $1,6002025-04-19 CRITICAL 9.8 CVE-2025-3819 A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown… Men Salon Management System No fix yet Fix from $2,3002025-04-19 HIGH 8.8 CVE-2025-3817 A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processi… Online Eyewear Shop No fix yet Fix from $1,9502025-04-19 CRITICAL 9.8 CVE-2025-3800 A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/cont… Wcms No fix yet Fix from $2,3002025-04-19 CRITICAL 9.8 CVE-2025-3799 A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousControl… Wcms No fix yet Fix from $2,3002025-04-19 HIGH 7.2 CVE-2025-3797 A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=de… Seacms after 13.3 Fix from $1,9502025-04-19 HIGH 7.5 CVE-2025-2010 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resu… Mitigation only Fix from $1,9502025-04-19 HIGH 8.8 CVE-2025-3796 A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/… Men Salon Management System No fix yet Fix from $1,9502025-04-18 MEDIUM 6.5 CVE-2025-32389 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injectio… Nameless 2.1.4+ Fix from $1,6002025-04-18 HIGH 7.2 CVE-2025-3792 A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin… Seacms after 13.3 Fix from $1,9502025-04-18 CRITICAL 9.3 CVE-2025-39471 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal Survey modal-survey.This issue… Mitigation only Fix from $2,3002025-04-18 CRITICAL 9.8 CVE-2025-28009 A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20. Dietiqa Mitigation only Fix from $2,3002025-04-17 HIGH 7.2 CVE-2025-29181 FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php. Foxcms after 1.25 Fix from $1,9502025-04-17 HIGH 7.2 CVE-2025-29180 In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters… Foxcms after 1.25 Fix from $1,9502025-04-17 CRITICAL 9.3 CVE-2025-39595 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows SQL … Mitigation only Fix from $2,3002025-04-17 HIGH 8.5 CVE-2025-39569 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows Blin… Mitigation only Fix from $1,9502025-04-17 HIGH 8.5 CVE-2025-39586 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profile… Mitigation only Fix from $1,9502025-04-17 CRITICAL 9.3 CVE-2025-39587 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calculator Builder cost-calculato… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.3 CVE-2025-32665 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator office-locator all… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.3 CVE-2025-32636 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic local-magic allows SQL… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-32626 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Manager js-jobs allows SQL Injec… Js Job Manager after 2.0.2 Fix from $2,3002025-04-17 HIGH 8.5 CVE-2025-32573 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. Th… Mitigation only Fix from $1,9502025-04-17 CRITICAL 9.3 CVE-2025-27302 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Marrero CHATLIVE chatlive allows… Mitigation only Fix from $2,3002025-04-17