5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-47862
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.

CVE-2022-42064
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

CVE-2022-4050
JoomSport Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.2%
2022 1 PoC

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-1768
RSVPMaker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.1%
2022 CWE-89 1 PoC

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

CVE-2022-43774
Delta Electronics DIAEnergie Database
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

CVE-2022-43215
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

CVE-2022-42245
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

CVE-2022-40032
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
64.0%
2022 4 PoCs

SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.

CVE-2022-42109
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.

CVE-2022-4118
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop Web Database Windows
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

CVE-2022-4117
IWS Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2022 1 PoC

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

CVE-2022-40943
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2022-32224
https://github.com/rails/rails Web Database
9.8
CRITICAL
EPSS
1.9%
2022 CWE-502 1 PoC

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

CVE-2022-24627
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
48.7%
2022 0 PoCs

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

CVE-2022-46887
Software Genérico Web Database
9.8
CRITICAL
EPSS
2.8%
2022 1 PoC

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.

CVE-2025-61548
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This vulnerability allows remote attackers to execute arbitrary SQL commands

CVE-2025-70892
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

CVE-2024-36058
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.

CVE-2024-38889
Software Genérico Database
9.6
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

CVE-2024-29824
🔥 KEV EPM Database ⚡ nuclei
9.6
CRITICAL
EPSS
94.0%
2024 3 PoCs

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.