Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2025-26607 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W… Wegia 3.2.13+ Fix from $2,3002025-02-18 CRITICAL 9.8 CVE-2025-26608 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W… Wegia 3.2.13+ Fix from $2,3002025-02-18 HIGH 8.5 CVE-2025-22639 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerc… Mitigation only Fix from $1,9502025-02-18 CRITICAL 9.8 CVE-2024-55460 A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attacke… Mitigation only Fix from $2,3002025-02-18 MEDIUM 6.7 CVE-2025-22207 Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. Mitigation only Fix from $1,6002025-02-18 HIGH 8.8 CVE-2024-13369 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all ver… Tour Master 5.3.8+ Fix from $1,9502025-02-18 CRITICAL 9.8 CVE-2025-1023 A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL In… Churchcrm after 5.13.0 Fix from $2,3002025-02-18 MEDIUM 6.5 CVE-2024-13595 The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and i… Simple Signup Form after 1.6.5 Fix from $1,6002025-02-18 CRITICAL 9.8 CVE-2025-25221 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If t… Luxcal Web Calendar 5.3.3l / 5.3.3m+ Fix from $2,3002025-02-18 CRITICAL 9.8 CVE-2025-25222 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php.… Luxcal Web Calendar 5.3.3l / 5.3.3m+ Fix from $2,3002025-02-18 HIGH 7.5 CVE-2025-1381 A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. This affects an unknown pa… Real Estate Property Management System No fix yet Fix from $1,9502025-02-17 CRITICAL 9.8 CVE-2025-1379 A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability… Real Estate Property Management System No fix yet Fix from $2,3002025-02-17 CRITICAL 9.8 CVE-2025-1380 A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of t… Gym Management System No fix yet Fix from $2,3002025-02-17 HIGH 8.6 CVE-2024-13726 The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action av… Themes Coder after 1.3.4 Fix from $1,9502025-02-17 HIGH 8.8 CVE-2025-1389 Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read… Orca Hcm 11.0+ Fix from $1,9502025-02-17 HIGH 7.5 CVE-2025-1374 A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of th… Real Estate Property Management System No fix yet Fix from $1,9502025-02-17 HIGH 7.6 CVE-2025-26755 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Airbnb Review Slider wp-airbnb-rev… Mitigation only Fix from $1,9502025-02-16 CRITICAL 9.3 CVE-2025-22290 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQ… Mitigation only Fix from $2,3002025-02-16 HIGH 7.5 CVE-2025-1356 A vulnerability was found in needyamin Library Card System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality o… Library Card System No fix yet Fix from $1,9502025-02-16 HIGH 7.5 CVE-2024-13488 The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all… Ltl Freight Quotes 3.3.8+ Fix from $1,9502025-02-15 MEDIUM 6.5 CVE-2024-13500 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time… Wp Project Manager 2.6.18+ Fix from $1,6002025-02-15 HIGH 8.8 CVE-2025-26156 A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to exe… Online Shopping Portal Project No fix yet Fix from $1,9502025-02-14 MEDIUM 5.9 CVE-2025-26157 A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote atta… Beauty Parlour Management System No fix yet Fix from $1,6002025-02-14 MEDIUM 5.1 CVE-2025-25991 SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component. Hoosk No fix yet Fix from $1,6002025-02-14 MEDIUM 5.1 CVE-2025-25992 SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component. Feminer Wms No fix yet Fix from $1,6002025-02-14 MEDIUM 5.1 CVE-2025-25993 SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid." Feminer Wms No fix yet Fix from $1,6002025-02-14 HIGH 7.5 CVE-2025-25994 SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id. Feminer Wms No fix yet Fix from $1,9502025-02-14 HIGH 8.8 CVE-2025-25206 eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authentica… Elabftw 5.1.15+ Fix from $1,9502025-02-14 CRITICAL 10.0 CVE-2024-13152 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring … Mitigation only Fix from $2,3002025-02-14 MEDIUM 6.5 CVE-2025-0821 Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to i… Bit Assist 1.5.3+ Fix from $1,6002025-02-14