476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-36934
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.9%
2023 0 PoCs

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVE-2021-24943
Registrations for the Events Calendar – Event Registration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
55.5%
2021 CWE-89 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVE-2021-24442
Poll, Survey, Questionnaire and Voting system Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.5%
2021 CWE-89 1 PoC

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

CVE-2021-24295
Spam protection, AntiSpam, FireWall by CleanTalk Web Networking Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
40.6%
2021 CWE-89 1 PoC

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

CVE-2021-24666
Podlove Podcast Publisher Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2021 CWE-89 1 PoC

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

CVE-2021-27315
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.

CVE-2021-37589
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
77.7%
2021 2 PoCs

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVE-2021-31316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
59.4%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

CVE-2021-24862
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 CWE-89 2 PoCs

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVE-2022-0826
WP Video Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2022 CWE-89 1 PoC

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2019-10232
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2019 0 PoCs

Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

CVE-2022-0412
TI WooCommerce Wishlist Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-89 2 PoCs

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

CVE-2021-41648
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
75.4%
2021 4 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

CVE-2013-3827
Software Genérico DevOps Database ⚡ nuclei
N/A
UNKNOWN
EPSS
86.8%
2013 2 PoCs

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

CVE-2015-9323
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2015 0 PoCs

The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

CVE-2023-40749
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

CVE-2021-36748
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2021 2 PoCs

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

CVE-2021-24340
WP Statistics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2021 CWE-89 1 PoC

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.3%
2021 CWE-89 3 PoCs

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVE-2021-42667
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2021 4 PoCs

A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.