2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-89 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-34989
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

CVE-2024-21216
Oracle WebLogic Server Database
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-29863
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 2 PoCs

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

CVE-2026-27847
MR9600 Database
9.8
CRITICAL
EPSS
0.1%
2026 CWE-89 1 PoC

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CVE-2023-34751
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

CVE-2025-65236
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.

CVE-2023-46347
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.3%
2023 1 PoC

In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2024-39250
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
88.4%
2024 1 PoC

EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

CVE-2024-6159
Push Notification for Post and BuddyPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
9.8%
2024 1 PoC

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2021-2029
Scripting Web Database
9.8
CRITICAL
EPSS
1.9%
2021 1 PoC

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-61246
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

CVE-2024-31750
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2024 0 PoCs

SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.

CVE-2023-41014
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

CVE-2024-57768
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2023-27638
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.

CVE-2023-24201
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

CVE-2025-22953
Software Genérico Database
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.

CVE-2024-25239
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.