5189 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-37777
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands.

CVE-2023-30150
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
49.3%
2023 1 PoC

PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

CVE-2023-27843
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.

CVE-2023-24780
Software Genérico Database
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.

CVE-2023-34362
🔥 KEV Software Genérico Database Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 15 PoCs

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in M

CVE-2023-3197
MStore API – Create Native Android & iOS Apps On The Cloud Web Database Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
32.4%
2023 CWE-89 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-28662
Gift Cards (Gift Vouchers and Packages) WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.3%
2023 1 PoC

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

CVE-2023-30192
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
41.9%
2023 1 PoC

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2023-41503
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

CVE-2023-36361
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

CVE-2023-1934
PnPSCADA Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential in

CVE-2023-41014
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

CVE-2023-27638
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.

CVE-2023-27667
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.

CVE-2023-50030
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection.

CVE-2023-49547
Software Genérico Web Database
9.8
CRITICAL
EPSS
7.6%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

CVE-2023-27570
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.

CVE-2023-0600
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.4%
2023 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

CVE-2023-0037
10Web Map Builder for Google Maps Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
65.6%
2023 1 PoC

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection