Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.2 CVE-2025-13192 The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to generic … Mitigation only Fix from $1,9502026-02-05 HIGH 8.8 CVE-2026-25514 FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL … Facturascripts 2025.81+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-25513 FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL … Facturascripts 2025.81+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-22044 GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This… Glpi 10.0.23+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2025-69213 OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerabilit… Openstamanager after 2.9.8 Fix from $1,9502026-02-04 HIGH 8.8 CVE-2025-69215 OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vul… Openstamanager after 2.9.8 Fix from $1,9502026-02-04 CRITICAL 9.8 CVE-2025-5329 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation … Mitigation only Fix from $2,3002026-02-04 HIGH 7.5 CVE-2025-15268 The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API action in all versions up to,… Mitigation only Fix from $1,9502026-02-04 HIGH 8.2 CVE-2020-37083 PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through t… No fix yet Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2020-37089 School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu… School Erp Pro Mitigation only Fix from $2,3002026-02-03 HIGH 8.2 CVE-2020-37076 Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database… Victor Cms No fix yet Fix from $1,9502026-02-03 HIGH 7.1 CVE-2020-37081 Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers t… No fix yet Fix from $1,9502026-02-03 HIGH 8.2 CVE-2019-25260 OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious da… No fix yet Fix from $1,9502026-02-03 CRITICAL 10.0 CVE-2025-10878 A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parame… Fikir Odalari Adminpando after 1.0.1 Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25238 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription d… Pearweb 1.33.0+ Fix from $2,3002026-02-03 HIGH 7.5 CVE-2026-25239 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue inser… Pearweb 1.33.0+ Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2026-25240 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::ma… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25241 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<packa… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25236 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25234 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion … Pearweb 1.33.0+ Fix from $2,3002026-02-03 MEDIUM 6.5 CVE-2025-70311 JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do … Jeewms Mitigation only Fix from $1,6002026-02-03 CRITICAL 9.8 CVE-2025-63624 SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute… Iot Smart Water Meter Firmware Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-57529 YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validatio… Cpas Audit Management System after 4.9 Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37110 60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through … 60cyclecms Mitigation only Fix from $2,3002026-02-03 MEDIUM 6.5 CVE-2020-37112 GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unva… Open Eclass Platform No fix yet Fix from $1,6002026-02-03 HIGH 7.1 CVE-2020-37105 PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL com… No fix yet Fix from $1,9502026-02-03 HIGH 7.1 CVE-2020-37108 PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows remote attackers to manipulate… No fix yet Fix from $1,9502026-02-03 HIGH 8.5 CVE-2026-25022 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-manageme… Mitigation only Fix from $1,9502026-02-03 MEDIUM 5.4 CVE-2026-1207EPSS 13% An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS… Django 4.2.28 / 5.2.11+ Fix from $1,6002026-02-03 MEDIUM 5.4 CVE-2026-1287 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column alias… Django 4.2.28 / 5.2.11+ Fix from $1,6002026-02-03