Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.5 CVE-2025-1670 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and i… Wpschoolpress after 2.2.16 Fix from $1,6002025-03-15 HIGH 8.7 CVE-2024-54445 Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the at… Mitigation only Fix from $1,9502025-03-14 HIGH 7.1 CVE-2024-54446 Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi techniq… Mitigation only Fix from $1,9502025-03-14 HIGH 7.1 CVE-2024-54447 Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique t… Mitigation only Fix from $1,9502025-03-14 HIGH 8.7 CVE-2024-12245 Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the a… Mitigation only Fix from $1,9502025-03-14 HIGH 7.2 CVE-2022-29059 An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6… Fortiweb 7.0.2+ Fix from $1,9502025-03-14 CRITICAL 9.8 CVE-2024-13321 The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to, and including, 2.0.0 due to… Analyticswp 2.1.0+ Fix from $2,3002025-03-14 HIGH 7.5 CVE-2025-2221 The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, … Wpcom Member 1.7.7+ Fix from $1,9502025-03-14 MEDIUM 6.8 CVE-2025-30022 CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter. Auto Atendimento No fix yet Fix from $1,6002025-03-14 CRITICAL 9.8 CVE-2025-26163 CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter. Auto Atendimento No fix yet Fix from $2,3002025-03-14 MEDIUM 6.1 CVE-2025-28011 A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote at… User Registration \& Login And User Management System No fix yet Fix from $1,6002025-03-13 MEDIUM 6.5 CVE-2025-24974 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize a… Dataease 2.10.6+ Fix from $1,6002025-03-13 MEDIUM 6.5 CVE-2025-27103 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allo… Dataease 2.10.6+ Fix from $1,6002025-03-13 HIGH 7.5 CVE-2025-2106 The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all ve… Mitigation only Fix from $1,9502025-03-13 HIGH 7.5 CVE-2025-2107 The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResultAndDie() function in all ver… Mitigation only Fix from $1,9502025-03-13 CRITICAL 10.0 CVE-2025-22954EPSS 26% GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid … Mitigation only Fix from $2,3002025-03-12 CRITICAL 9.8 CVE-2025-2217 A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessR… Warehouse Refinement Management System No fix yet Fix from $2,3002025-03-12 MEDIUM 6.5 CVE-2021-37787 The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request… Abo.cms after 5.9.3 Fix from $1,6002025-03-11 HIGH 8.8 CVE-2025-27617 Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cau… Pimcore 11.5.4+ Fix from $1,9502025-03-11 HIGH 8.8 CVE-2024-54026 An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.… Fortisandbox 4.4.7+ Fix from $1,9502025-03-11 MEDIUM 6.7 CVE-2024-33501 Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4… Fortianalyzer 7.2.6 / 7.2.8+ Fix from $1,6002025-03-11 MEDIUM 5.3 CVE-2025-22370 Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL co… Mitigation only Fix from $1,6002025-03-11 HIGH 7.2 CVE-2025-2132 A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists o… Ftcms No fix yet Fix from $1,9502025-03-09 HIGH 8.8 CVE-2025-2126EPSS 11% A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the f… Jux Real Estate Mitigation only Fix from $1,9502025-03-09 HIGH 7.3 CVE-2025-2118 A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown part of the file /admin/login… Mitigation only Fix from $1,9502025-03-09 MEDIUM 6.3 CVE-2025-2117 A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affe… Mitigation only Fix from $1,6002025-03-09 CRITICAL 9.8 CVE-2025-2113 A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this issue is some unknown functiona… Atsvd after 3.4.1 Fix from $2,3002025-03-09 CRITICAL 9.8 CVE-2025-2112 A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declared as critical. Affected by t… Yaoqishan 2020-02-29+ Fix from $2,3002025-03-08 CRITICAL 9.8 CVE-2025-1323 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versio… Wp Recall 16.26.12+ Fix from $2,3002025-03-08 CRITICAL 9.8 CVE-2025-2088 A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affected is an unknown function of… Pre School Enrollment System No fix yet Fix from $2,3002025-03-07