Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-1821
A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the fil…
Zz
after 2024-8
HIGH 8.8
CVE-2025-1820
A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the f…
Zz
after 2024-8
HIGH 8.8
CVE-2025-1812
A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of the file com/futvan/z/framew…
Zz
2024-8+
HIGH 7.3
CVE-2025-1811
A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been declared as critical. Affected by this vulnerability is an unknown …
Mitigation only
HIGH 7.3
CVE-2025-1809
A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projeto…
Mitigation only
HIGH 7.3
CVE-2025-1808
A vulnerability has been found in Pixsoft E-Saphira 1.7.24 and classified as critical. This vulnerability affects unknown code of the file /servlet?a…
Mitigation only
MEDIUM 6.3
CVE-2025-1797
A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operati…
Mitigation only
MEDIUM 6.5
CVE-2024-13750
The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versi…
Mitigation only
MEDIUM 5.1
CVE-2025-26047
Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
Loggrove
No fix yet
HIGH 8.8
CVE-2025-1572
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions …
Kivicare
3.6.8+
CRITICAL 9.8
CVE-2024-55160
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
Gfast
after 3.2
CRITICAL 9.8
CVE-2024-13148
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL…
Mitigation only
CRITICAL 9.8
CVE-2025-1751
A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update an…
Mitigation only
MEDIUM 5.5
CVE-2025-25462
A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers t…
Land Record System
No fix yet
CRITICAL 9.8
CVE-2025-25516
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
Seacms
after 13.3
CRITICAL 9.8
CVE-2025-25517
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
Seacms
after 13.3
CRITICAL 9.8
CVE-2025-25519
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
Seacms
after 13.3
CRITICAL 9.8
CVE-2025-25520
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
Seacms
after 13.3
CRITICAL 9.8
CVE-2025-25521
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
Seacms
after 13.3
MEDIUM 6.5
CVE-2025-25514
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
Seacms
after 13.3
HIGH 8.8
CVE-2025-25515
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
Seacms
after 13.3
CRITICAL 9.8
CVE-2025-27135
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL componen…
Ragflow
after 0.15.1
CRITICAL 9.8
CVE-2025-26971
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker poll-maker allows Blind SQL …
Poll Maker
5.6.6+
CRITICAL 9.3
CVE-2025-26974
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-sto…
Mitigation only
CRITICAL 9.3
CVE-2025-26943
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes easy-quotes allows Bl…
Mitigation only
HIGH 7.6
CVE-2025-26946
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider wp-yelp-review-…
Mitigation only
HIGH 8.5
CVE-2025-26915
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Inject…
Mitigation only
HIGH 7.5
CVE-2025-1648
The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficie…
Yawave
after 2.9.1
HIGH 7.2
CVE-2025-22210
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arb…
Hikashop
after 5.1.4
CRITICAL 9.8
CVE-2025-1640
A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some unknown functionality of the fi…
Modernanet
1.1.1+