Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
MEDIUM 6.3 CVE-2025-0404 A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the function CoachController of the… Mitigation only Fix from $1,6002025-01-13 HIGH 8.8 CVE-2025-0405 A vulnerability was found in liujianview gymxmjpa 1.0 and classified as critical. This issue affects the function GoodsDaoImpl of the file src/main/j… Gymxmjpa No fix yet Fix from $1,9502025-01-13 HIGH 8.8 CVE-2025-0392 A vulnerability, which was classified as critical, was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. Affected is the functio… Jeewms 2025-01-01+ Fix from $1,9502025-01-11 HIGH 8.8 CVE-2025-0391 A vulnerability, which was classified as critical, has been found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This issue affects… Jeewms 2025-01-01+ Fix from $1,9502025-01-11 HIGH 8.8 CVE-2025-0103 An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as pas… Expedition 1.2.101+ Fix from $1,9502025-01-11 HIGH 7.5 CVE-2024-12404 The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all versions up to, and includin… Mitigation only Fix from $1,9502025-01-11 HIGH 8.3 CVE-2024-9134 Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL… Ng Firewall 17.2+ Fix from $1,9502025-01-10 MEDIUM 6.5 CVE-2024-12473 The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin fo… Mitigation only Fix from $1,6002025-01-10 MEDIUM 6.3 CVE-2024-54762 Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter S… Ruoyi after 4.7.9 Fix from $1,6002025-01-09 MEDIUM 6.3 CVE-2024-54761 BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. Bigant Office Messenger 5 No fix yet Fix from $1,6002025-01-09 HIGH 8.8 CVE-2025-21628 Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator pas… Chatwoot 3.16.0+ Fix from $1,9502025-01-09 HIGH 8.5 CVE-2025-22535 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal wplistcal allows SQL Injectio… Mitigation only Fix from $1,9502025-01-09 HIGH 8.5 CVE-2025-22537 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-map… Mitigation only Fix from $1,9502025-01-09 CRITICAL 9.3 CVE-2025-22540 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in seballero Emailing Subscription email-suscripci… Mitigation only Fix from $2,3002025-01-09 CRITICAL 9.3 CVE-2025-22542 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ofek Nakar Virtual Bot virtual-bot allows Blind… Mitigation only Fix from $2,3002025-01-09 HIGH 8.5 CVE-2025-22505 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlis… Mitigation only Fix from $1,9502025-01-09 HIGH 7.6 CVE-2025-22527 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing… Mitigation only Fix from $1,9502025-01-09 MEDIUM 6.5 CVE-2024-12067 The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary… Mitigation only Fix from $1,6002025-01-09 CRITICAL 9.8 CVE-2025-0347 A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulnerability affects unknown code… Admission Management System No fix yet Fix from $2,3002025-01-09 HIGH 8.8 CVE-2025-0345 A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function listData of the file /sys/menu/li… Cy Fast No fix yet Fix from $1,9502025-01-09 HIGH 8.8 CVE-2025-0344 A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file… Cy Fast No fix yet Fix from $1,9502025-01-09 CRITICAL 9.8 CVE-2025-0340 A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown fu… Cinema Seat Reservation System Mitigation only Fix from $2,3002025-01-09 CRITICAL 9.8 CVE-2025-0336 A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pa… Project Management System No fix yet Fix from $2,3002025-01-09 HIGH 8.8 CVE-2025-0334 A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file… Cy Fast No fix yet Fix from $1,9502025-01-09 HIGH 8.8 CVE-2025-0333 A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData… Cy Fast No fix yet Fix from $1,9502025-01-09 HIGH 8.0 CVE-2024-13204 A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functi… E Commerce Php No fix yet Fix from $1,9502025-01-09 HIGH 8.8 CVE-2024-13194 A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_memb… Sucms No fix yet Fix from $1,9502025-01-09 HIGH 8.8 CVE-2025-22141 WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, s… Wegia 3.2.8+ Fix from $1,9502025-01-08 HIGH 8.8 CVE-2025-22140 WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php en… Wegia 3.2.8+ Fix from $1,9502025-01-08 HIGH 8.8 CVE-2024-55517 An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGC… Mitigation only Fix from $1,9502025-01-08