5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-44541
Software Genérico Database
9.8
CRITICAL
EPSS
2.9%
2024 1 PoC

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

CVE-2024-54820
Software Genérico Database
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

CVE-2024-4548
DIAEnergie Database
9.8
CRITICAL
EPSS
45.0%
2024 CWE-20 1 PoC

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

CVE-2024-38289
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.3%
2024 0 PoCs

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

CVE-2024-44921
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

CVE-2024-25843
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

CVE-2024-48307
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 1 PoC

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

CVE-2024-21508
mysql2 Database
9.8
CRITICAL
EPSS
46.2%
2024 CWE-94 2 PoCs

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVE-2024-57035
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2024-25239
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

CVE-2024-39907
1Panel Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 CWE-89 0 PoCs

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

CVE-2024-52335
syngo.plaza VB30E Database
9.8
CRITICAL
EPSS
1.2%
2024 CWE-89 1 PoC

A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.

CVE-2024-29303
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection

CVE-2024-36678
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2024-0705
Payment Gateway of Stripe for WooCommerce Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.7%
2024 CWE-89 0 PoCs

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6809
Simple Video Directory Web Database Windows
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-1301
Monitool Database
9.8
CRITICAL
EPSS
33.2%
2024 CWE-89 1 PoC

SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.

CVE-2024-33266
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.

CVE-2024-44812
Software Genérico Web Database
9.8
CRITICAL
EPSS
18.7%
2024 1 PoC

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.