657 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-47866
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.

CVE-2022-36787
webvendome Database
9.8
CRITICAL
EPSS
0.2%
2022 CWE-89 1 PoC

webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

CVE-2022-31181
PrestaShop Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
78.3%
2022 CWE-89 0 PoCs

PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.

CVE-2022-3254
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.6%
2022 CWE-89 1 PoC

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

CVE-2022-1453
RSVPMaker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
61.0%
2022 CWE-89 0 PoCs

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

CVE-2022-40877
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

CVE-2022-3481
WooCommerce Dropshipping Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
48.0%
2022 1 PoC

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

CVE-2022-30004
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2022 2 PoCs

Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

CVE-2022-47859
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.

CVE-2022-4357
LetsRecover Web Database Windows
9.8
CRITICAL
EPSS
2.1%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-4445
FL3R FeelBox Web Database Windows
9.8
CRITICAL
EPSS
4.7%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-43212
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

CVE-2022-40872
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.

CVE-2022-45136
Apache Jena SDB Web Database
9.8
CRITICAL
EPSS
2.0%
2022 CWE-502 1 PoC

Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of attack. As a result an application using Apache Jena SDB can be subject to RCE when connected to a malicious database server. Apache Jena SDB has been EOL since December 2020 and users should migrate to alternative options e.g. Apache Jena TDB 2.

CVE-2022-4297
WP AutoComplete Search Web Database Windows
9.8
CRITICAL
EPSS
3.1%
2022 2 PoCs

The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection

CVE-2022-47770
Software Genérico Database
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.

CVE-2022-37204
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.1%
2022 2 PoCs

Final CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-42122
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.

CVE-2022-43214
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.

CVE-2022-40347
Software Genérico Web Database
9.8
CRITICAL
EPSS
5.8%
2022 2 PoCs

SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.