476 vulnerabilidades · Database · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-1061
Software Genérico Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
83.4%
2024 CWE-89 1 PoC

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

CVE-2021-29442
nacos Database ⚡ nuclei
8.6
HIGH
EPSS
92.8%
2021 CWE-306 1 PoC

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)

CVE-2025-14124
Team Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
10.3%
2025 1 PoC

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2023-24000
GamiPress Database ⚡ nuclei
8.2
HIGH
EPSS
21.2%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

CVE-2024-43965
SendGrid for WordPress Web Database Windows ⚡ nuclei
8.2
HIGH
EPSS
18.4%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.

CVE-2022-45805
Paytm Payment Gateway Database ⚡ nuclei
8.2
HIGH
EPSS
2.8%
2022 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.

CVE-2014-3120
🔥 KEV Software Genérico Database ⚡ nuclei
8.1
HIGH
EPSS
82.6%
2014 4 PoCs

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVE-2021-39165
Cachet Web Database ⚡ nuclei
8.1
HIGH
EPSS
89.4%
2021 CWE-287 2 PoCs

Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.

CVE-2022-31101
blockwishlist Database ⚡ nuclei
8.1
HIGH
EPSS
53.9%
2022 CWE-89 2 PoCs

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-21661
wordpress-develop Web Database Windows ⚡ nuclei
8.0
HIGH
EPSS
90.5%
2022 CWE-89 21 PoCs

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.

CVE-2021-31581
Provisioning Manager Engine (PME) Database ⚡ nuclei
7.9
HIGH
EPSS
9.2%
2021 CWE-269 0 PoCs

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

CVE-2024-27718
Software Genérico Web Database ⚡ nuclei
7.8
HIGH
EPSS
6.3%
2024 0 PoCs

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

CVE-2023-37270
Piwigo Web Database ⚡ nuclei
7.6
HIGH
EPSS
59.2%
2023 CWE-89 0 PoCs

Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be log in to the administrator screen, even with low privileges. Any SQL statement can be executed. Doing so may leak information from the database. Version 13.8.0 contains a fix

CVE-2024-6205
PayPlus Payment Gateway Web Database Windows ⚡ nuclei
7.6
HIGH
EPSS
90.4%
2024 2 PoCs

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

CVE-2023-22047
PeopleSoft Enterprise PT PeopleTools Web Database ⚡ nuclei
7.5
HIGH
EPSS
91.6%
2023 2 PoCs

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-34133
GMS Networking Database ⚡ nuclei
7.5
HIGH
EPSS
64.3%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVE-2023-5203
WP Sessions Time Monitoring Full Automatic Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
42.9%
2023 1 PoC

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

CVE-2024-8484
REST API TO MiniProgram Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
88.8%
2024 CWE-89 1 PoC

The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-32737
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
51.6%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.

CVE-2024-13496
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
19.3%
2024 CWE-89 1 PoC

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This vulnerability was previously published as being fi