476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-38637
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

CVE-2022-32025
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

CVE-2022-38812
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2022 1 PoC

AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-27985
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-0949
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
62.5%
2022 CWE-89 1 PoC

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection

CVE-2022-28032
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.7%
2022 0 PoCs

AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php

CVE-2022-0773
Documentor – Create Product Documentation Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.5%
2022 CWE-89 1 PoC

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

CVE-2022-0827
Bestbooks Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.0%
2022 CWE-89 1 PoC

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-24266
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
37.4%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

CVE-2022-27927
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2022 2 PoCs

A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.

CVE-2022-0786
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.2%
2022 CWE-89 1 PoC

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

CVE-2022-0769
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2022 CWE-89 1 PoC

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CVE-2022-0439
Email Subscribers & Newsletters Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.2%
2022 2 PoCs

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

CVE-2022-22897
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2022 2 PoCs

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.

CVE-2022-1692
CP Image Store with Slideshow Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 2 PoCs

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attack