476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24666
Podlove Podcast Publisher Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2021 CWE-89 1 PoC

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

CVE-2021-27315
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.

CVE-2021-37589
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
77.7%
2021 2 PoCs

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVE-2021-31316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
59.4%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

CVE-2021-24862
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 CWE-89 2 PoCs

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVE-2021-41648
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
75.4%
2021 4 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

CVE-2021-36748
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2021 2 PoCs

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

CVE-2021-24340
WP Statistics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2021 CWE-89 1 PoC

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.3%
2021 CWE-89 3 PoCs

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVE-2021-42667
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2021 4 PoCs

A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-24731
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.1%
2021 CWE-89 1 PoC

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

CVE-2021-24627
G Auto-Hyperlink Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-89 2 PoCs

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-24915
Contest Gallery – Photo Contest Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.6%
2021 CWE-89 1 PoC

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

CVE-2021-25899
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
73.0%
2021 2 PoCs

An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1.

CVE-2021-27314
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2021 1 PoC

SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

CVE-2021-3110
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.9%
2021 3 PoCs

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

CVE-2021-45811
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

CVE-2021-43510
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2021 2 PoCs

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2021-24827
Asgaros Forum Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue