2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-30502
WP Travel Engine Database ⚡ nuclei
9.3
CRITICAL
EPSS
18.4%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.

CVE-2024-55976
Critical Site Intel Database
9.3
CRITICAL
EPSS
35.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mikeleembruggen Critical Site Intel critical-site-intel-stats allows SQL Injection.This issue affects Critical Site Intel: from n/a through <= 1.0.

CVE-2024-6912
ProcessPlus Database Windows
9.3
CRITICAL
EPSS
0.3%
2024 CWE-798 2 PoCs

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-51818
Fancy Product Designer Database
9.3
CRITICAL
EPSS
19.3%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.

CVE-2024-30490
ProfileGrid Database ⚡ nuclei
9.3
CRITICAL
EPSS
14.4%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

CVE-2024-49681
WP Sessions Time Monitoring Full Automatic Database
9.3
CRITICAL
EPSS
51.3%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.

CVE-2024-58308
Quick.CMS Web Database
9.3
CRITICAL
EPSS
0.2%
2024 CWE-89 1 PoC

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.

CVE-2024-58290
Xhibiter NFT Marketplace Database
9.3
CRITICAL
EPSS
0.0%
2024 CWE-89 1 PoC

Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.

CVE-2024-33544
WZone Database
9.3
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

CVE-2024-55972
eTemplates Database
9.3
CRITICAL
EPSS
10.9%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chriscarvache eTemplates etemplates allows SQL Injection.This issue affects eTemplates: from n/a through <= 0.2.1.

CVE-2024-58301
Purei CMS Web Database
9.3
CRITICAL
EPSS
0.0%
2024 CWE-89 1 PoC

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

CVE-2024-54292
Appsplate Database
9.3
CRITICAL
EPSS
5.2%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsplate Appsplate appsplate allows SQL Injection.This issue affects Appsplate: from n/a through <= 2.1.3.

CVE-2024-32709
WP-Recall Database ⚡ nuclei
9.3
CRITICAL
EPSS
92.9%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.

CVE-2024-55981
Nabz Image Gallery Database
9.3
CRITICAL
EPSS
25.2%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery nabz-image-gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through <= v1.00.

CVE-2024-32128
Realtyna Organic IDX plugin Database ⚡ nuclei
9.3
CRITICAL
EPSS
11.0%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.

CVE-2024-55988
Navayan CSV Export Database
9.3
CRITICAL
EPSS
32.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.

CVE-2024-55980
Wr Age Verification Database
9.3
CRITICAL
EPSS
6.5%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0.

CVE-2024-30498
CRM Perks Forms Database ⚡ nuclei
9.3
CRITICAL
EPSS
15.0%
2024 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

CVE-2021-47748
GraphQL Database
9.3
CRITICAL
EPSS
0.2%
2021 CWE-78 1 PoC

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM functionality.

CVE-2021-47708
Smart Home IoT Control System Database
9.3
CRITICAL
EPSS
0.1%
2021 CWE-89 2 PoCs

COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL code through the 'id' parameter in 'loginstart.asp'. Attackers can exploit this by sending a POST request with malicious 'id' values to manipulate database queries and gain unauthorized access.