5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-55460
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.

CVE-2024-45256
Software Genérico Web Database
9.8
CRITICAL
EPSS
50.9%
2024 1 PoC

An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.

CVE-2024-24112
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
81.6%
2024 0 PoCs

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

CVE-2024-51064
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

CVE-2024-7456
lunary-ai/lunary Web Database
9.8
CRITICAL
EPSS
29.3%
2024 CWE-89 1 PoC

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

CVE-2024-1698
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 5 PoCs

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-45918
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

CVE-2024-37858
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 2 PoCs

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

CVE-2024-6670
🔥 KEV WhatsUp Gold Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2024 CWE-89 1 PoC

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CVE-2024-21216
Oracle WebLogic Server Database
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-48509
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Learning with Texts (LWT) 2.0.3 is vulnerable to SQL Injection. This occurs when the application fails to properly sanitize user inputs, allowing attackers to manipulate SQL queries by injecting malicious SQL statements into URL parameters. By exploiting this vulnerability, an attacker could gain unauthorized access to the database, retrieve sensitive information, modify or delete data, and execute arbitrary commands.

CVE-2024-51211
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
4.1%
2024 1 PoC

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

CVE-2024-35056
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.

CVE-2024-45622
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
57.4%
2024 0 PoCs

ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

CVE-2024-35469
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2024 2 PoCs

A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

CVE-2024-45265
Software Genérico Web Database
9.8
CRITICAL
EPSS
17.6%
2024 1 PoC

A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

CVE-2024-3552
Web Directory Free Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 4 PoCs

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 10 PoCs

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-36681
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.

CVE-2019-2729
WebLogic Server Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2019 10 PoCs

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).