476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0783
Multiple Shipping Address Woocommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.5%
2022 CWE-89 1 PoC

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.3%
2021 CWE-89 3 PoCs

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2021-24827
Asgaros Forum Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2021-24285
Car Seller - Auto Classifieds Script Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2021 CWE-89 1 PoC

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

CVE-2021-24731
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.1%
2021 CWE-89 1 PoC

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

CVE-2021-24915
Contest Gallery – Photo Contest Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.6%
2021 CWE-89 1 PoC

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

CVE-2021-27316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

CVE-2021-31856
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2021 1 PoC

A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

CVE-2023-36306
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

CVE-2021-41460
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.7%
2021 0 PoCs

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

CVE-2021-24554
Paytm – Donation Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-89 2 PoCs

The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

CVE-2021-22145
Elasticsearch Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2021 CWE-200 3 PoCs

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVE-2021-27124
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 3 PoCs

SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.

CVE-2021-37291
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2021 1 PoC

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

CVE-2021-42663
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.0%
2021 3 PoCs

An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.

CVE-2021-34187
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2021 1 PoC

main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.