2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-21395
Communications Operations Monitor Web Database
7.2
HIGH
EPSS
1.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-21410
Database - Enterprise Edition Database
7.2
HIGH
EPSS
1.2%
2022 1 PoC

Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Sharding. Successful attacks of this vulnerability can result in takeover of Oracle Database - Enterprise Edition Sharding. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:

CVE-2022-43279
Software Genérico Web Database
7.2
HIGH
EPSS
0.3%
2022 1 PoC

LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.

CVE-2022-3764
Form Vibes Database
7.2
HIGH
EPSS
0.6%
2022 1 PoC

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

CVE-2022-39179
College Management System v1.0 Web Database
7.2
HIGH
EPSS
1.4%
2022 1 PoC

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

CVE-2022-28132
Software Genérico Database
7.2
HIGH
EPSS
0.1%
2022 2 PoCs

The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.

CVE-2022-4352
Qe SEO Handyman Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-4546
Mapwiz Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2022-4547
Conditional Payment Methods for WooCommerce Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 1 PoC

The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin.

CVE-2022-3131
Search Logger – Know What Your Visitors Search Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-45889
Software Genérico Database
7.2
HIGH
EPSS
1.2%
2022 1 PoC

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

CVE-2022-3689
HTML Forms Web Database Windows
7.2
HIGH
EPSS
40.3%
2022 3 PoCs

The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-3300
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Web Database Windows
7.2
HIGH
EPSS
0.8%
2022 CWE-89 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-21603
Database - Enterprise Edition Database
7.2
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Oracle Database - Sharding component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Local Logon to compromise Oracle Database - Sharding. Successful attacks of this vulnerability can result in takeover of Oracle Database - Sharding. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-21596
Database - Enterprise Edition Database
7.2
HIGH
EPSS
1.3%
2022 1 PoC

Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having DBA user privilege with network access via Oracle Net to compromise Oracle Database - Advanced Queuing. Successful attacks of this vulnerability can result in takeover of Oracle Database - Advanced Queuing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-3858
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin.

CVE-2022-4355
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3249
WP CSV Exporter Web Database Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks

CVE-2022-4370
multimedial images Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2022-4351
Qe SEO Handyman Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin