16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-3211
WordPress Database Administrator Web Database Windows
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-52335
syngo.plaza VB30E Database
9.8
CRITICAL
EPSS
1.2%
2024 CWE-89 1 PoC

A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.

CVE-2023-43373
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.2%
2023 0 PoCs

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

CVE-2015-4852
🔥 KEV Software Genérico Web Database
9.8
CRITICAL
EPSS
92.9%
2015 10 PoCs

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVE-2015-2590
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
61.7%
2015 2 PoCs

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

CVE-2023-27637
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.

CVE-2023-27569
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

CVE-2023-37777
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands.

CVE-2023-30150
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
49.3%
2023 1 PoC

PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

CVE-2023-47253
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2023 4 PoCs

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

CVE-2023-27779
Software Genérico Database
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

CVE-2024-21508
mysql2 Database
9.8
CRITICAL
EPSS
46.2%
2024 CWE-94 2 PoCs

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVE-2024-8503
VICIdial Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2024 CWE-89 3 PoCs

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

CVE-2015-1427
🔥 KEV Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.3%
2015 9 PoCs

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVE-2024-40498
Software Genérico Web Database
9.8
CRITICAL
EPSS
11.8%
2024 1 PoC

SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php

CVE-2023-50027
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.

CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2024-57035
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

CVE-2023-21890
Communications Converged Application Server Database
9.8
CRITICAL
EPSS
2.8%
2023 1 PoC

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Communications Converged Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:

CVE-2024-24142
Software Genérico Database
9.8
CRITICAL
EPSS
10.3%
2024 1 PoC

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.