16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-2549
WebLogic Server Web Database
7.2
HIGH
EPSS
1.3%
2020 2 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). The supported version that is affected is 10.3.6.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-9022
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
7.2
HIGH
EPSS
1.6%
2024 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11269
AHAthat Plugin Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.

CVE-2024-23116
Centreon Database
7.2
HIGH
EPSS
86.0%
2024 CWE-89 1 PoC

Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLCARelation function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22296.

CVE-2024-12773
Altra Side Menu Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-7766
Adicon Server Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2022-21600
MySQL Server Database
7.2
HIGH
EPSS
1.3%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-34022
Software Genérico Database
7.2
HIGH
EPSS
0.3%
2022 1 PoC

SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive.

CVE-2022-4359
WP RSS By Publishers Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2024-11372
Connexion Logs Web Database Windows
7.2
HIGH
EPSS
1.3%
2024 1 PoC

The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-8625
TS Poll Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
2.9%
2024 1 PoC

The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2019-15985
Cisco Data Center Network Manager Web Networking Database
7.2
HIGH
EPSS
2.1%
2019 CWE-89 1 PoC

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published sim

CVE-2024-55104
Software Genérico Web Database
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.

CVE-2024-23117
Centreon Database
7.2
HIGH
EPSS
87.4%
2024 CWE-89 1 PoC

Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactServiceCommands function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22297.

CVE-2024-10499
AI Engine Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2022-4356
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3243
Import all XML, CSV & TXT into WordPress Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

CVE-2022-3150
WP Custom Cursors | WordPress Cursor Plugin Web Database Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

CVE-2022-4372
Web Invoice Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well

CVE-2024-42994
Software Genérico Database
7.2
HIGH
EPSS
0.1%
2024 1 PoC

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.