476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-44349
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2024 2 PoCs

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

CVE-2024-6159
Push Notification for Post and BuddyPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
9.8%
2024 1 PoC

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-4434
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.1%
2024 CWE-89 1 PoC

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-3495
Country State City Dropdown CF7 Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2024 CWE-89 2 PoCs

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6671
WhatsUp Gold Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2024 CWE-89 0 PoCs

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CVE-2024-8911
LatePoint Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
30.9%
2024 CWE-89 0 PoCs

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note that changing a WordPress user's password is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. Without this setting enabled, only the pass

CVE-2024-5827
vanna-ai/vanna Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.9%
2024 CWE-89 0 PoCs

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead to command execution or the creation of backdoors.

CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-89 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-32640
MasaCMS Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 6 PoCs

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

CVE-2024-35286
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
63.8%
2024 0 PoCs

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

CVE-2024-38289
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.3%
2024 0 PoCs

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

CVE-2024-48307
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 1 PoC

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

CVE-2024-39907
1Panel Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 CWE-89 0 PoCs

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

CVE-2024-0705
Payment Gateway of Stripe for WooCommerce Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.7%
2024 CWE-89 0 PoCs

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-24112
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
81.6%
2024 0 PoCs

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

CVE-2024-1698
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 5 PoCs

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6670
🔥 KEV WhatsUp Gold Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2024 CWE-89 1 PoC

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CVE-2024-51211
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
4.1%
2024 1 PoC

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

CVE-2024-45622
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
57.4%
2024 0 PoCs

ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

CVE-2024-3552
Web Directory Free Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 4 PoCs

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.