Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-30364 WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/ht… Wegia 3.2.8+ Fix from $2,3002025-03-27 CRITICAL 9.8 CVE-2025-30365 WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/ht… Wegia 3.2.8+ Fix from $2,3002025-03-27 HIGH 8.8 CVE-2025-22783 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrl… Seo Plugin By Squirrly Seo after 12.4.03 Fix from $1,9502025-03-27 CRITICAL 9.8 CVE-2025-25686 semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. Semcms after 5.0 Fix from $2,3002025-03-27 HIGH 8.8 CVE-2025-2854 A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functio… Payroll Management System No fix yet Fix from $1,9502025-03-27 HIGH 7.6 CVE-2025-22652 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kendysond Payment Forms for Paystack payment-fo… Mitigation only Fix from $1,9502025-03-27 HIGH 8.8 CVE-2025-2847 A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing o… Gym Management System No fix yet Fix from $1,9502025-03-27 CRITICAL 9.8 CVE-2025-2846 A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of t… Online Eyewear Shop No fix yet Fix from $2,3002025-03-27 HIGH 7.6 CVE-2025-30921 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters newsletters-lite… Mitigation only Fix from $1,9502025-03-27 HIGH 7.6 CVE-2025-30879 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-… Mitigation only Fix from $1,9502025-03-27 HIGH 7.6 CVE-2025-30843 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in setriosoft bizcalendar-web bizcalendar-web allo… Mitigation only Fix from $1,9502025-03-27 HIGH 8.5 CVE-2025-30819 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways giveasap allows SQL… Mitigation only Fix from $1,9502025-03-27 HIGH 8.5 CVE-2025-30806 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vim… Mitigation only Fix from $1,9502025-03-27 HIGH 8.5 CVE-2025-30810 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders Inc., Lead Form Data Collection to … Mitigation only Fix from $1,9502025-03-27 HIGH 7.6 CVE-2025-30791 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce cart-trac… Mitigation only Fix from $1,9502025-03-27 HIGH 8.5 CVE-2025-30784 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Shuffle WP Subscription Forms wp-subscriptio… Mitigation only Fix from $1,9502025-03-27 HIGH 8.5 CVE-2025-30775 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite… Mitigation only Fix from $1,9502025-03-27 HIGH 7.6 CVE-2025-30765 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPPOOL FlexStock stock-sync-with-google-sheet-f… Mitigation only Fix from $1,9502025-03-27 CRITICAL 9.8 CVE-2025-2831 A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified a… Library Management System No fix yet Fix from $2,3002025-03-27 HIGH 7.5 CVE-2025-30217 Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe … Frappe 14.93.2 / 15.55.0+ Fix from $1,9502025-03-26 CRITICAL 9.3 CVE-2025-30524 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog displayproduct allow… Mitigation only Fix from $2,3002025-03-26 CRITICAL 9.3 CVE-2025-28942 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCo… Mitigation only Fix from $2,3002025-03-26 HIGH 8.5 CVE-2025-28939 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EuroCizia WP Google Calendar Manager wp-gcalend… Mitigation only Fix from $1,9502025-03-26 CRITICAL 9.3 CVE-2025-28898 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-sto… Mitigation only Fix from $2,3002025-03-26 HIGH 8.5 CVE-2025-28873 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Scott Taylor Shuffle shuffle allows Blind SQL I… Mitigation only Fix from $1,9502025-03-26 CRITICAL 9.3 CVE-2025-26941 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin allows SQL… Mitigation only Fix from $2,3002025-03-26 CRITICAL 9.3 CVE-2025-28904 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free web-directory-free … Mitigation only Fix from $2,3002025-03-25 HIGH 7.5 CVE-2025-30212 Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 an… Frappe 14.89.0 / 15.51.0+ Fix from $1,9502025-03-25 CRITICAL 9.8 CVE-2024-42533 SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code v… Mitigation only Fix from $2,3002025-03-25 HIGH 8.8 CVE-2024-53678 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte… Vcl 2.5.2+ Fix from $1,9502025-03-25