2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-23331
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.

CVE-2023-27637
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.

CVE-2023-30194
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
75.2%
2023 1 PoC

Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

CVE-2023-1020
Steveas WP Live Chat Shoutbox Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
82.2%
2023 1 PoC

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2023-27203
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

CVE-2023-30189
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().

CVE-2023-34750
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

CVE-2023-34756
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVE-2023-51801
Software Genérico Web Database
9.8
CRITICAL
EPSS
7.2%
2023 1 PoC

SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.

CVE-2023-43373
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.2%
2023 0 PoCs

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

CVE-2023-3047
Lockcell Database
9.8
CRITICAL
EPSS
8.8%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.This issue affects Lockcell: before 15.

CVE-2023-51951
Software Genérico Web Database
9.8
CRITICAL
EPSS
3.5%
2023 2 PoCs

SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.

CVE-2023-2297
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Web Database Windows
9.8
CRITICAL
EPSS
0.6%
2023 CWE-620 1 PoC

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme insta

CVE-2023-24200
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

CVE-2024-24142
Software Genérico Database
9.8
CRITICAL
EPSS
10.3%
2024 1 PoC

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

CVE-2024-41702
SiberianCMS v5.0.8 Web Database
9.8
CRITICAL
EPSS
0.2%
2024 CWE-89 1 PoC

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-30163
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
46.4%
2024 1 PoC

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.

CVE-2024-53499
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

CVE-2024-4295
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 CWE-89 3 PoCs

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-5765
WpStickyBar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
78.2%
2024 1 PoC

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection