Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2025-22371 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allow… Mitigation only Fix from $2,3002025-04-14 MEDIUM 6.3 CVE-2025-3571 A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnera… Mitigation only Fix from $1,6002025-04-14 CRITICAL 9.8 CVE-2025-3559 A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListCont… Uzy Ssm Mall No fix yet Fix from $2,3002025-04-14 CRITICAL 9.8 CVE-2025-3553 A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of the file /admin.php?m… Phpshe No fix yet Fix from $2,3002025-04-14 MEDIUM 6.3 CVE-2025-3534 A vulnerability, which was classified as critical, was found in PowerCreator CMS 1.0. Affected is an unknown function of the file /OpenPublicCourse.a… Mitigation only Fix from $1,6002025-04-13 MEDIUM 6.5 CVE-2025-2128 The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter in all versions up to, and i… Mitigation only Fix from $1,6002025-04-11 HIGH 8.5 CVE-2025-32681 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log Viewer error-log-viewer-wp al… Mitigation only Fix from $1,9502025-04-11 HIGH 8.5 CVE-2025-32650 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Accessibility Suite online-accessi… Mitigation only Fix from $1,9502025-04-11 HIGH 8.5 CVE-2025-32618 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Inject… Mitigation only Fix from $1,9502025-04-11 CRITICAL 9.3 CVE-2025-32603 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users Stats wp-online-users-stats … Mitigation only Fix from $2,3002025-04-11 HIGH 8.5 CVE-2025-32567 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in dev02ali Easy Post Duplicator easy-post-duplica… Mitigation only Fix from $1,9502025-04-11 HIGH 8.5 CVE-2025-32558 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ketanajani Duplicate Title Checker duplicate-ti… Mitigation only Fix from $1,9502025-04-11 CRITICAL 9.3 CVE-2025-32565 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-desig… Mitigation only Fix from $2,3002025-04-11 CRITICAL 9.3 CVE-2025-31565 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-con… Mitigation only Fix from $2,3002025-04-11 CRITICAL 9.3 CVE-2025-31599 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows… Mitigation only Fix from $2,3002025-04-11 HIGH 8.5 CVE-2025-32687 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce r… Mitigation only Fix from $1,9502025-04-10 HIGH 7.6 CVE-2025-32128 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby Locations nearby-locations all… Mitigation only Fix from $1,9502025-04-10 HIGH 8.2 CVE-2025-32119 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce card… Mitigation only Fix from $1,9502025-04-10 HIGH 7.6 CVE-2025-32685 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aristo Rinjuang WP Inquiries wp-inquiries allow… Mitigation only Fix from $1,9502025-04-09 HIGH 7.6 CVE-2025-32676 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Picture-Planet GmbH Verowa Connect verowa-conne… Mitigation only Fix from $1,9502025-04-09 HIGH 7.6 CVE-2025-32677 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solwininfotech WP Social Stream Designer social… Mitigation only Fix from $1,9502025-04-09 HIGH 7.2 CVE-2025-32550 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin al… Mitigation only Fix from $1,9502025-04-09 HIGH 8.8 CVE-2025-29390 jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php. Erp No fix yet Fix from $1,9502025-04-09 HIGH 7.2 CVE-2025-29391 horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php. Library Manager No fix yet Fix from $1,9502025-04-09 HIGH 7.6 CVE-2025-29189 Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores. Flowise after 2.2.3 Fix from $1,9502025-04-09 HIGH 7.3 CVE-2017-20197 A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. Thi… Patch available Fix from $1,9502025-04-09 CRITICAL 9.8 CVE-2025-25226 Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected … Joomla\! 2.2.0 / 3.4.0+ Fix from $2,3002025-04-08 CRITICAL 9.3 CVE-2025-32020 The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/… Mitigation only Fix from $2,3002025-04-08 HIGH 7.2 CVE-2025-22461 SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privile… Endpoint Manager 2022+ Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2025-3436 The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in all … Mitigation only Fix from $1,6002025-04-08