Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-1821 A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the fil… Zz after 2024-8 Fix from $2,3002025-03-02 HIGH 8.8 CVE-2025-1820 A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the f… Zz after 2024-8 Fix from $1,9502025-03-02 HIGH 8.8 CVE-2025-1812 A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of the file com/futvan/z/framew… Zz 2024-8+ Fix from $1,9502025-03-02 HIGH 7.3 CVE-2025-1811 A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this vulnerability is an unknown … Mitigation only Fix from $1,9502025-03-02 HIGH 7.3 CVE-2025-1809 A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projeto… Mitigation only Fix from $1,9502025-03-02 HIGH 7.3 CVE-2025-1808 A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?a… Mitigation only Fix from $1,9502025-03-02 MEDIUM 6.3 CVE-2025-1797 A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operati… Mitigation only Fix from $1,6002025-03-01 MEDIUM 6.5 CVE-2024-13750 The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versi… Mitigation only Fix from $1,6002025-03-01 MEDIUM 5.1 CVE-2025-26047 Loggrove v1.0 is vulnerable to SQL Injection in the read.py file. Loggrove No fix yet Fix from $1,6002025-02-28 HIGH 8.8 CVE-2025-1572 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions … Kivicare 3.6.8+ Fix from $1,9502025-02-28 CRITICAL 9.8 CVE-2024-55160 GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list. Gfast after 3.2 Fix from $2,3002025-02-27 CRITICAL 9.8 CVE-2024-13148 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL… Mitigation only Fix from $2,3002025-02-27 CRITICAL 9.8 CVE-2025-1751 A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update an… Mitigation only Fix from $2,3002025-02-27 MEDIUM 5.5 CVE-2025-25462 A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers t… Land Record System No fix yet Fix from $1,6002025-02-26 CRITICAL 9.8 CVE-2025-25516 Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. Seacms after 13.3 Fix from $2,3002025-02-25 CRITICAL 9.8 CVE-2025-25517 Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. Seacms after 13.3 Fix from $2,3002025-02-25 CRITICAL 9.8 CVE-2025-25519 Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. Seacms after 13.3 Fix from $2,3002025-02-25 CRITICAL 9.8 CVE-2025-25520 Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. Seacms after 13.3 Fix from $2,3002025-02-25 CRITICAL 9.8 CVE-2025-25521 Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. Seacms after 13.3 Fix from $2,3002025-02-25 MEDIUM 6.5 CVE-2025-25514 Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. Seacms after 13.3 Fix from $1,6002025-02-25 HIGH 8.8 CVE-2025-25515 Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. Seacms after 13.3 Fix from $1,9502025-02-25 CRITICAL 9.8 CVE-2025-27135 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL componen… Ragflow after 0.15.1 Fix from $2,3002025-02-25 CRITICAL 9.8 CVE-2025-26971 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker poll-maker allows Blind SQL … Poll Maker 5.6.6+ Fix from $2,3002025-02-25 CRITICAL 9.3 CVE-2025-26974 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-sto… Mitigation only Fix from $2,3002025-02-25 CRITICAL 9.3 CVE-2025-26943 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Bl… Mitigation only Fix from $2,3002025-02-25 HIGH 7.6 CVE-2025-26946 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider wp-yelp-review-… Mitigation only Fix from $1,9502025-02-25 HIGH 8.5 CVE-2025-26915 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Inject… Mitigation only Fix from $1,9502025-02-25 HIGH 7.5 CVE-2025-1648 The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficie… Yawave after 2.9.1 Fix from $1,9502025-02-25 HIGH 7.2 CVE-2025-22210 A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arb… Hikashop after 5.1.4 Fix from $1,9502025-02-25 CRITICAL 9.8 CVE-2025-1640 A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some unknown functionality of the fi… Modernanet 1.1.1+ Fix from $2,3002025-02-25