Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-04-28 CVE-2025-4039 SQL Injection vulnerability in PHPgurukul Rail Pass Management System 1.0
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-04-28 CVE-2025-4026 SQL Injection vulnerability in PHPgurukul Nipah Virus Testing Management System 1.0
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-04-28 CVE-2025-4027 SQL Injection vulnerability in PHPgurukul OLD AGE Home Management System 1.0
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-04-28 CVE-2025-4020 SQL Injection vulnerability in PHPgurukul OLD AGE Home Management System 1.0
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-04-27 CVE-2025-3968 SQL Injection vulnerability in Code-Projects News Publishing Site Dashboard 1.0
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0.
network
low complexity
code-projects CWE-89
8.8
2025-04-27 CVE-2025-3955 SQL Injection vulnerability in Code-Projects Patient Record Management System 1.0
A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0.
network
low complexity
code-projects CWE-89
7.5
2025-04-24 CVE-2025-3280 The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
6.5
2025-04-23 CVE-2025-32968 SQL Injection vulnerability in Xwiki
XWiki is a generic wiki platform.
network
low complexity
xwiki CWE-89
8.8
2025-04-23 CVE-2025-32969 SQL Injection vulnerability in Xwiki
XWiki is a generic wiki platform.
network
low complexity
xwiki CWE-89
critical
9.8
2025-04-22 CVE-2025-46242 SQL Injection vulnerability in Kibokolabs Watu Quiz
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz allows SQL Injection.
network
low complexity
kibokolabs CWE-89
4.9