5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-24656
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.

CVE-2023-0381
GigPress Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks

CVE-2023-54359
WordPress adivaha Travel Plugin Web Database Windows
8.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' values using XOR-based payloads to extract sensitive database information or cause denial of service.

CVE-2023-28663
Formidable PRO2PDF WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
0.8%
2023 1 PoC

The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.

CVE-2023-23490
Survey Maker WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.4%
2023 1 PoC

The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.

CVE-2023-29842
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2023 3 PoCs

ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

CVE-2023-2921
Short URL Web Database Windows
8.8
HIGH
EPSS
0.3%
2023 1 PoC

The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.

CVE-2023-26217
TIBCO EBX Add-ons Database Windows
8.8
HIGH
EPSS
0.2%
2023 CWE-89 1 PoC

The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0.

CVE-2023-0955
WP Statistics Web Database Windows
8.8
HIGH
EPSS
1.5%
2023 1 PoC

The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.

CVE-2023-49548
Software Genérico Web Database
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

CVE-2023-24654
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.

CVE-2023-54163
NLB mKlik Makedonija Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 2 PoCs

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.

CVE-2023-24652
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.

CVE-2023-30625
rudder-server Database ⚡ nuclei
8.8
HIGH
EPSS
88.2%
2023 CWE-89 1 PoC

rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.

CVE-2023-54333
Social-Share-Buttons Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted POST requests with malicious SQL payloads to retrieve and potentially steal entire database contents.

CVE-2023-24364
Software Genérico Database
8.8
HIGH
EPSS
0.4%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.

CVE-2023-0220
Pinpoint Booking System Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

CVE-2023-0875
WP Meta SEO Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnerability that can be exploited by subscriber+ users.

CVE-2023-32697
sqlite-jdbc Database
8.8
HIGH
EPSS
5.5%
2023 CWE-94 1 PoC

SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.

CVE-2023-0953
Devolutions Server Database
8.8
HIGH
EPSS
0.7%
2023 1 PoC

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.