2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2025-34102
CryptoLog Web Database
9.3
CRITICAL
EPSS
69.0%
2025 CWE-89 1 PoC

A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and command injection vulnerabilities. An unauthenticated attacker can gain shell access as the web server user by first exploiting a SQL injection flaw in login.php to bypass authentication, followed by command injection in logshares_ajax.php to execute arbitrary operating system commands. The login bypass is achieved by submitting crafted SQL via the user POST parameter. Once authenticated, the attacker can abuse the lsid POST parameter in the logs

CVE-2025-1023
ChurchCRM Database ⚡ nuclei
9.3
CRITICAL
EPSS
2.8%
2025 CWE-89 0 PoCs

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.

CVE-2025-32969
xwiki-platform Database ⚡ nuclei
9.3
CRITICAL
EPSS
31.4%
2025 CWE-89 0 PoCs

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database backend, including when "Prevent unregistered users from viewing pages, regardless of the page rights" and "Prevent unregistered users from editing pages, regardless of the page rights" options are enabled. Depending on the used database backend, the attacker may be able to not only obtain confidential information

CVE-2025-54726
JS Archive List Database ⚡ nuclei
9.3
CRITICAL
EPSS
0.9%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6.

CVE-2025-34205
Print Virtual Appliance Host DevOps Web Database
9.3
CRITICAL
EPSS
6.5%
2025 CWE-561 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code present in multiple Docker-hosted PHP instances. A script named /var/www/app/resetroot.php (found in several containers) lacks authentication checks and, when executed, performs a SQL update that sets the database administrator username to 'root' and its password hash to the SHA-512 hash of the string 'password'. Separately, commented-out code in /var/www/app/lib/common/oses.php would unserialize session data (unser

CVE-2025-32429
xwiki-platform Database ⚡ nuclei
9.3
CRITICAL
EPSS
28.1%
2025 CWE-89 3 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

CVE-2025-22785
Course Booking System Database ⚡ nuclei
9.3
CRITICAL
EPSS
11.6%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course Booking System course-booking-system allows SQL Injection.This issue affects Course Booking System: from n/a through <= 6.0.6.

CVE-2025-34162
Bian Que Feijiu Intelligent Emergency and Quality Control System Database
9.3
CRITICAL
EPSS
0.7%
2025 CWE-89 1 PoC

An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails to properly sanitize user-supplied input in the strOpid parameter, allowing attackers to inject arbitrary SQL statements. This can lead to data exfiltration, authentication bypass, and potentially remote code execution, depending on backend configuration. The vulnerability is presumed to affect builds released prior to June 2025 and is said to

CVE-2025-10351
Melis Platform Web Database
9.3
CRITICAL
EPSS
0.0%
2025 CWE-89 2 PoCs

SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint.

CVE-2025-34206
Print Virtual Appliance Host DevOps Web Database
9.3
CRITICAL
EPSS
0.2%
2025 CWE-732 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers. An attacker who controls or reaches any container can read or modify these artifacts, leading to credential theft, RCE via Laravel APP_KEY, Portainer takeover, and full compromise.

CVE-2025-3096
Clinic's Patient Management System Database
9.3
CRITICAL
EPSS
62.6%
2025 CWE-89 1 PoC

Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.

CVE-2018-25128
SOCA Access Control System Web Database Cloud
9.3
CRITICAL
EPSS
0.1%
2018 CWE-89 2 PoCs

SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalidated POST parameters. Attackers can bypass authentication, retrieve password hashes, and gain administrative access with full system privileges by exploiting injection flaws in Login.php and Card_Edit_GetJson.php.

CVE-2022-33965
WP Visitor Statistics (WordPress plugin) Web Database Windows ⚡ nuclei
9.3
CRITICAL
EPSS
42.7%
2022 CWE-89 0 PoCs

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

CVE-2024-9465
🔥 KEV Expedition Web Networking Database ⚡ nuclei
9.2
CRITICAL
EPSS
94.3%
2024 CWE-89 5 PoCs

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVE-2023-36645
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

CVE-2023-23459
Priority for Windows Database Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-89 1 PoC

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2024-51060
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

CVE-2024-32848
EPM Database
9.1
CRITICAL
EPSS
50.8%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-36840
Software Genérico Web Database
9.1
CRITICAL
EPSS
11.6%
2024 4 PoCs

SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.

CVE-2024-5315
ERP CMS Web Database ⚡ nuclei
9.1
CRITICAL
EPSS
63.0%
2024 CWE-89 0 PoCs

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.