2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-4797
Newsletters Web Database Windows
7.2
HIGH
EPSS
0.6%
2023 1 PoC

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

CVE-2023-2832
unilogies/bumsys Database
7.2
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.

CVE-2023-4691
WordPress Online Booking and Scheduling Plugin Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-3820
pimcore/pimcore Database
7.2
HIGH
EPSS
41.2%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-2655
Contact Form by WD Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-1408
Video List Manager Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
12.4%
2023 1 PoC

The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0329
Elementor Website Builder Web Database Windows
7.2
HIGH
EPSS
9.1%
2023 2 PoCs

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

CVE-2023-1211
phpipam/phpipam Web Database
7.2
HIGH
EPSS
0.3%
2023 CWE-89 2 PoCs

SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.

CVE-2023-2114
NEX-Forms Web Database Windows
7.2
HIGH
EPSS
48.9%
2023 2 PoCs

The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.

CVE-2023-27709
Software Genérico Web Database
7.2
HIGH
EPSS
1.6%
2023 1 PoC

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.

CVE-2023-1207
HTTP Headers Web Database Windows
7.2
HIGH
EPSS
0.3%
2023 1 PoC

This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.

CVE-2023-5082
History Log by click5 Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 1 PoC

The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

CVE-2023-21932
Hospitality OPERA 5 Property Services Web Database
7.2
HIGH
EPSS
24.4%
2023 1 PoC

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported version that is affected is 5.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. While the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Or

CVE-2023-0771
ampache/ampache Database
7.2
HIGH
EPSS
0.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.

CVE-2023-0900
Pricing Table Builder Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
6.4%
2023 1 PoC

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.

CVE-2024-12735
Advance Post Prefix Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks

CVE-2024-0566
Smart Manager Web Database Windows
7.2
HIGH
EPSS
2.5%
2024 2 PoCs

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2024-24139
Software Genérico Database
7.2
HIGH
EPSS
7.5%
2024 1 PoC

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

CVE-2024-55103
Software Genérico Web Database
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.

CVE-2024-42994
Software Genérico Database
7.2
HIGH
EPSS
0.1%
2024 1 PoC

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.