Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.3 CVE-2024-58301 Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user in… No fix yet Fix from $2,3002025-12-11 CRITICAL 9.3 CVE-2024-58290 Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queri… No fix yet Fix from $2,3002025-12-11 CRITICAL 9.8 CVE-2025-14537 A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the … Class And Exam Timetable Management System Mitigation only Fix from $2,3002025-12-11 CRITICAL 9.8 CVE-2025-14536 A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerability is an unknown functional… Class And Exam Timetable Management System Mitigation only Fix from $2,3002025-12-11 HIGH 8.8 CVE-2025-13214 IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which coul… Aspera Orchestrator 4.1.1+ Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-14529 A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_runn… Retro Basketball Shoes Online Store Mitigation only Fix from $2,3002025-12-11 CRITICAL 9.8 CVE-2025-14527 A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_boo… Advanced Library Management System Mitigation only Fix from $2,3002025-12-11 CRITICAL 9.8 CVE-2025-14515 A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /a… Supplier Management System Mitigation only Fix from $2,3002025-12-11 CRITICAL 9.8 CVE-2025-14514 A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manip… Supplier Management System Mitigation only Fix from $2,3002025-12-11 MEDIUM 6.5 CVE-2025-10163 The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter of the catlist shortcode in … Mitigation only Fix from $1,6002025-12-11 HIGH 7.8 CVE-2025-67644 LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.… Langgraph Checkpoint Sqlite 3.0.1+ Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-65950 WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with perm… Wbce Cms 1.6.5+ Fix from $1,9502025-12-10 HIGH 8.8 CVE-2025-67501 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain an SQL Injection vul… Wegia 3.5.5+ Fix from $1,9502025-12-10 MEDIUM 6.5 CVE-2021-47704 OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL co… Openbmcs No fix yet Fix from $1,6002025-12-09 CRITICAL 9.3 CVE-2021-47708 COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL … No fix yet Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14337 A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulat… Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14335 A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14336 A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.ph… Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14334 A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipula… Student Management System Mitigation only Fix from $2,3002025-12-09 HIGH 7.2 CVE-2025-64156 An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, For… Fortivoice after 7.2.1 Fix from $1,9502025-12-09 CRITICAL 9.8 CVE-2025-63742 SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain… Rockoa Mitigation only Fix from $2,3002025-12-09 HIGH 8.5 CVE-2025-67518 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accordion Slider PRO accordion_sli… Mitigation only Fix from $1,9502025-12-09 HIGH 7.6 CVE-2025-67519 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allow… Mitigation only Fix from $1,9502025-12-09 HIGH 7.6 CVE-2025-67520 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tiny Solutions Media Library Tools media-librar… Mitigation only Fix from $1,9502025-12-09 HIGH 8.5 CVE-2025-67516 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store… Mitigation only Fix from $1,9502025-12-09 HIGH 8.5 CVE-2025-67517 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget all… Mitigation only Fix from $1,9502025-12-09 HIGH 8.5 CVE-2025-62093 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background … Mitigation only Fix from $1,9502025-12-09 CRITICAL 9.8 CVE-2025-12504 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection. Thi… Mitigation only Fix from $2,3002025-12-09 HIGH 8.7 CVE-2025-12807 A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through expos… Mitigation only Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-10655 SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL state… Helpdesk Patch available Fix from $1,9502025-12-09