5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2018-25199
OOP CMS BLOG Web Database
8.8
HIGH
EPSS
0.2%
2018 CWE-89 1 PoC

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.

CVE-2018-25187
Tina4 Stack Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes, or inject SQL code through the menu endpoint to manipulate database queries.

CVE-2018-25166
Meneame English Pligg Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to index.php with crafted SQL payloads in the search parameter to extract sensitive database information including usernames, database names, and version details.

CVE-2018-25209
OpenBiz Cubi Lite Web Database
8.8
HIGH
EPSS
0.4%
2018 CWE-89 1 PoC

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database information or bypass authentication.

CVE-2018-25183
Shipping System CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login endpoint to authenticate without valid credentials.

CVE-2018-25203
Online Store System CMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind SQL injection payloads in the email field to extract sensitive database information.

CVE-2018-25171
EdTv Database
8.8
HIGH
EPSS
0.1%
2018 CWE-434 1 PoC

EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the admin/edit_source endpoint with crafted SQL UNION statements to extract database information including schema names, user credentials, and version details.

CVE-2018-25170
DoceboLMS Web Database
8.8
HIGH
EPSS
0.0%
2018 CWE-352 1 PoC

DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id, idC, and idU parameters. Attackers can send GET requests to the lesson.php endpoint with malicious SQL payloads to extract sensitive database information.

CVE-2018-25300
XATABoost CMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.

CVE-2018-25192
GPS Tracking System Web Database
8.8
HIGH
EPSS
0.3%
2018 CWE-89 1 PoC

GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit crafted POST requests to the login.php endpoint with SQL injection payloads in the username field to gain unauthorized access without valid credentials.

CVE-2022-42121
Software Genérico Database
8.8
HIGH
EPSS
0.6%
2022 1 PoC

A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.

CVE-2022-3849
WP User Merger Web Database Windows
8.8
HIGH
EPSS
0.5%
2022 2 PoCs

The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

CVE-2022-48600
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-50895
Aero CMS Web Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.

CVE-2022-39822
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2022 1 PoC

In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.

CVE-2022-1578
My wpdb Web Database Windows
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

CVE-2022-50694
Impact/Pulse/First Web Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unauthorized database information.

CVE-2022-40043
Software Genérico Database
8.8
HIGH
EPSS
0.8%
2022 1 PoC

Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.

CVE-2022-3848
WP User Merger Web Database Windows
8.8
HIGH
EPSS
0.5%
2022 2 PoCs

The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

CVE-2022-39427
VM VirtualBox Database Windows
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows systems only. CVSS 3.1 Ba