476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2021-24285
Car Seller - Auto Classifieds Script Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2021 CWE-89 1 PoC

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

CVE-2021-27316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

CVE-2021-31856
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2021 1 PoC

A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

CVE-2021-41460
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.7%
2021 0 PoCs

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

CVE-2021-24554
Paytm – Donation Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-89 2 PoCs

The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

CVE-2021-22145
Elasticsearch Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2021 CWE-200 3 PoCs

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVE-2021-27124
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 3 PoCs

SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.

CVE-2021-37291
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2021 1 PoC

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

CVE-2021-42663
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.0%
2021 3 PoCs

An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.

CVE-2021-34187
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2021 1 PoC

main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

CVE-2021-24139
Photo Gallery by 10Web Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.4%
2021 CWE-89 1 PoC

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

CVE-2021-27319
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.

CVE-2021-24791
Header Footer Code Manager Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2021 CWE-89 1 PoC

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

CVE-2021-24946
Modern Events Calendar Lite Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
60.1%
2021 CWE-89 2 PoCs

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

CVE-2021-24849
WCFM Marketplace – Best Multivendor Marketplace for WooCommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.6%
2021 CWE-89 1 PoC

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

CVE-2017-3528
Applications Framework Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
43.2%
2017 2 PoCs

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks

CVE-2017-11444
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.3%
2017 0 PoCs

Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.