Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 7.2 CVE-2025-14898 A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderde… Real Estate Management System No fix yet Fix from $1,9502025-12-19 HIGH 7.2 CVE-2025-14897 A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/userage… Real Estate Management System No fix yet Fix from $1,9502025-12-19 MEDIUM 5.4 CVE-2025-63948 A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the … Phpmsadmin No fix yet Fix from $1,6002025-12-18 HIGH 8.8 CVE-2025-46268 Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands. Webaccess\/scada Mitigation only Fix from $1,9502025-12-18 MEDIUM 5.4 CVE-2023-53935 WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.… No fix yet Fix from $1,6002025-12-18 HIGH 8.8 CVE-2021-47711 A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method par… Xperience after 13.0.52 Fix from $1,9502025-12-18 CRITICAL 9.8 CVE-2025-14877 A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The… Supplier Management System Mitigation only Fix from $2,3002025-12-18 HIGH 8.5 CVE-2025-64371 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL I… Mitigation only Fix from $1,9502025-12-18 CRITICAL 9.3 CVE-2025-60062 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-wit… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.3 CVE-2025-58951 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management fo… Mitigation only Fix from $2,3002025-12-18 HIGH 8.5 CVE-2025-14314 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit popup-builder-block allows Blin… Mitigation only Fix from $1,9502025-12-18 CRITICAL 9.8 CVE-2025-14833 A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /… Online Appointment Booking System Mitigation only Fix from $2,3002025-12-17 HIGH 8.8 CVE-2025-14834 A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a man… Simple Stock System No fix yet Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2023-53926 PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database querie… Simple Cms Mitigation only Fix from $2,3002025-12-17 MEDIUM 6.5 CVE-2023-53917 Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate da… Affiliate Me No fix yet Fix from $1,6002025-12-17 HIGH 8.8 CVE-2025-68400 ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` i… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-68111 ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-68112 ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-67877 ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2025-14832 A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduc… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-17 HIGH 7.2 CVE-2025-66396 ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-66395 ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 7.3 CVE-2025-67285 A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for … Covid Tracking System Using Qr Code No fix yet Fix from $1,9502025-12-17 MEDIUM 6.3 CVE-2025-14780 A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /disht… Mitigation only Fix from $1,6002025-12-16 HIGH 8.5 CVE-2025-68054 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Back… Mitigation only Fix from $1,9502025-12-16 HIGH 8.5 CVE-2025-68055 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL… Mitigation only Fix from $1,9502025-12-16 HIGH 8.5 CVE-2025-68056 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominouts… Mitigation only Fix from $1,9502025-12-16 HIGH 7.6 CVE-2025-67999 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blin… Mitigation only Fix from $1,9502025-12-16 HIGH 8.5 CVE-2025-68053 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows … Mitigation only Fix from $1,9502025-12-16 HIGH 8.5 CVE-2025-67950 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-… Mitigation only Fix from $1,9502025-12-16