Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.5 CVE-2024-11939 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, … Mitigation only Fix from $1,9502025-01-08 MEDIUM 6.5 CVE-2024-12030 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute of the 'mdf_value' shortcode i… Wordpress Meta Data And Taxonomies Filter 1.3.3.6+ Fix from $1,6002025-01-08 HIGH 7.6 CVE-2025-22350 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injec… Mitigation only Fix from $1,9502025-01-07 HIGH 8.8 CVE-2025-0300 A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of… Online Book Shop No fix yet Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2025-0299 A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_resu… Online Book Shop No fix yet Fix from $2,3002025-01-07 HIGH 7.6 CVE-2025-22536 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiren.sabd WP Music Player wp-music-player allo… Mitigation only Fix from $1,9502025-01-07 HIGH 7.6 CVE-2025-22533 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bulktheme WOOEXIM wooexim allows SQL Injection.… Mitigation only Fix from $1,9502025-01-07 HIGH 8.5 CVE-2025-22519 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jerodmoore eDoc Easy Tables edoc-easy-tables al… Mitigation only Fix from $1,9502025-01-07 HIGH 7.6 CVE-2025-22507 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in iDo8p WPMU Prefill Post wpmu-prefill-post allow… Mitigation only Fix from $1,9502025-01-07 HIGH 7.6 CVE-2025-22502 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mindvalley MindValley Super PageMash mindvalley… Mitigation only Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2025-0298 A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the fil… Online Book Shop No fix yet Fix from $2,3002025-01-07 MEDIUM 6.3 CVE-2025-0297 A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the fil… Online Book Shop No fix yet Fix from $1,6002025-01-07 HIGH 7.2 CVE-2024-48245 Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, … Vehicle Management System Mitigation only Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2025-0296 A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /bookli… Online Book Shop No fix yet Fix from $2,3002025-01-07 HIGH 8.8 CVE-2025-0294 A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability… Home Clean Services Management System No fix yet Fix from $1,9502025-01-07 HIGH 8.5 CVE-2025-22348 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rtowebsites DynamicTags dynamictags allows Blin… Mitigation only Fix from $1,9502025-01-07 HIGH 7.6 CVE-2025-22349 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress Auction Plugin wp-auctions a… Mitigation only Fix from $1,9502025-01-07 HIGH 7.6 CVE-2025-22351 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contact Form 7 Database – CFDB7 adv… Mitigation only Fix from $1,9502025-01-07 HIGH 7.6 CVE-2025-22352 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edi… Mitigation only Fix from $1,9502025-01-07 CRITICAL 9.3 CVE-2024-56290 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing … Mitigation only Fix from $2,3002025-01-07 CRITICAL 9.3 CVE-2024-56284 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wireless SMS Notification ssl-wi… Mitigation only Fix from $2,3002025-01-07 HIGH 8.5 CVE-2024-51715 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale clickwhale allows Blind S… Clickwhale 2.4.2+ Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2024-8855 The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing edito… Wordpress Auction after 3.7 Fix from $2,3002025-01-07 MEDIUM 6.5 CVE-2024-12332 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and i… Wpschoolpress after 2.2.14 Fix from $1,6002025-01-07 HIGH 7.5 CVE-2024-12157 The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the… Mitigation only Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-12416 The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woomotiv_seen_products_.*' cookie… Mitigation only Fix from $1,9502025-01-07 MEDIUM 6.5 CVE-2024-12311 The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement,… Email Subscribers \& Newsletters 5.7.44+ Fix from $1,6002025-01-06 CRITICAL 9.8 CVE-2025-0233 A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pa… Project Management System No fix yet Fix from $2,3002025-01-05 HIGH 8.8 CVE-2025-0231 A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functio… Gym Management System No fix yet Fix from $1,9502025-01-05 HIGH 8.8 CVE-2025-0232 A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionali… Blood Bank Management System No fix yet Fix from $1,9502025-01-05