5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-25250
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

CVE-2024-37858
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 2 PoCs

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

CVE-2023-29863
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 2 PoCs

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

CVE-2023-4188
instantsoft/icms2 Web Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2021-44026
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
72.5%
2021 2 PoCs

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CVE-2025-69633
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions).

CVE-2023-27032
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
40.8%
2023 1 PoC

Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

CVE-2024-24401
Software Genérico Web Database
9.8
CRITICAL
EPSS
58.0%
2024 1 PoC

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

CVE-2024-7456
lunary-ai/lunary Web Database
9.8
CRITICAL
EPSS
29.3%
2024 CWE-89 1 PoC

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

CVE-2023-4490
WP Job Portal Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
41.1%
2023 1 PoC

The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2024-1698
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 5 PoCs

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-70149
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

CVE-2024-48307
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 1 PoC

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

CVE-2023-30192
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
41.9%
2023 1 PoC

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

CVE-2026-27847
MR9600 Database
9.8
CRITICAL
EPSS
0.1%
2026 CWE-89 1 PoC

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CVE-2024-22108
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 2 PoCs

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.

CVE-2023-24199
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

CVE-2024-6028
Quiz Maker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2024 CWE-89 2 PoCs

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-25239
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

CVE-2024-30990
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.