Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-05-05 CVE-2025-44074 SQL Injection vulnerability in Seacms 13.3
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
network
low complexity
seacms CWE-89
critical
9.8
2025-05-05 CVE-2025-45321 SQL Injection vulnerability in Lopalopa Online Service Management Portal 1.0
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.
network
low complexity
lopalopa CWE-89
8.8
2025-05-05 CVE-2025-45322 SQL Injection vulnerability in Lopalopa Online Service Management Portal 1.0
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.
network
low complexity
lopalopa CWE-89
8.8
2025-05-04 CVE-2025-4250 SQL Injection vulnerability in Fabian Nero Social Networking Site 1.0
A vulnerability was found in code-projects Nero Social Networking Site 1.0.
network
low complexity
fabian CWE-89
critical
9.8
2025-05-04 CVE-2025-4248 SQL Injection vulnerability in Chuck24 Simple To-Do List System 1.0
A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical.
network
low complexity
chuck24 CWE-89
critical
9.8
2025-05-04 CVE-2025-4247 SQL Injection vulnerability in Chuck24 Simple To-Do List System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0.
network
low complexity
chuck24 CWE-89
8.8
2025-05-03 CVE-2025-4242 SQL Injection vulnerability in PHPgurukul Online Birth Certificate System 2.0
A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-05-03 CVE-2025-4241 SQL Injection vulnerability in PHPgurukul Teacher Subject Allocation Management System 1.0
A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-05-03 CVE-2025-4226 SQL Injection vulnerability in PHPgurukul Cyber Cafe Management System 1.0
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-05-02 CVE-2025-4204 SQL Injection vulnerability in Auctionplugin Ultimate Wordpress Auction Plugin
The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
auctionplugin CWE-89
7.5