881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-1674
School Registration and Fee System Web Database
7.3
HIGH
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester School Registration and Fee System 1.0 and classified as critical. This issue affects some unknown processing of the file /bilal final/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224231.

CVE-2023-3693
Life Insurance Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Life Insurance Management System 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234244.

CVE-2023-7172
Hospital Management System Web Database
7.3
HIGH
EPSS
1.7%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Dashboard. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249356.

CVE-2023-4182
Inventory Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-236217 was assigned to this vulnerability.

CVE-2023-1207
HTTP Headers Web Database Windows
7.2
HIGH
EPSS
0.3%
2023 1 PoC

This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.

CVE-2023-2338
pimcore/pimcore Database
7.2
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-2492
QueryWall: Plug'n Play Firewall Web Networking Database Windows
7.2
HIGH
EPSS
0.2%
2023 2 PoCs

The QueryWall: Plug'n Play Firewall WordPress plugin through 1.1.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-21932
Hospitality OPERA 5 Property Services Web Database
7.2
HIGH
EPSS
24.4%
2023 1 PoC

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported version that is affected is 5.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. While the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Or

CVE-2023-5082
History Log by click5 Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 1 PoC

The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

CVE-2023-27709
Software Genérico Web Database
7.2
HIGH
EPSS
1.6%
2023 1 PoC

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.

CVE-2023-2114
NEX-Forms Web Database Windows
7.2
HIGH
EPSS
48.9%
2023 2 PoCs

The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.

CVE-2023-2221
WP Custom Cursors | WordPress Cursor Plugin Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 2 PoCs

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2023-1425
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins

CVE-2023-27707
Software Genérico Web Database
7.2
HIGH
EPSS
1.6%
2023 1 PoC

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.

CVE-2023-1211
phpipam/phpipam Web Database
7.2
HIGH
EPSS
0.3%
2023 CWE-89 2 PoCs

SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.

CVE-2023-6620
POST SMTP Mailer Web Database Windows
7.2
HIGH
EPSS
3.4%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-2655
Contact Form by WD Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-3673
pimcore/pimcore Database
7.2
HIGH
EPSS
11.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.

CVE-2023-0329
Elementor Website Builder Web Database Windows
7.2
HIGH
EPSS
9.1%
2023 2 PoCs

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

CVE-2023-2832
unilogies/bumsys Database
7.2
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.