881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-4797
Newsletters Web Database Windows
7.2
HIGH
EPSS
0.6%
2023 1 PoC

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

CVE-2023-6620
POST SMTP Mailer Web Database Windows
7.2
HIGH
EPSS
3.4%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-2114
NEX-Forms Web Database Windows
7.2
HIGH
EPSS
48.9%
2023 2 PoCs

The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.

CVE-2023-3673
pimcore/pimcore Database
7.2
HIGH
EPSS
11.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.

CVE-2023-0278
GeoDirectory Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-3820
pimcore/pimcore Database
7.2
HIGH
EPSS
41.2%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-1361
unilogies/bumsys Database
7.2
HIGH
EPSS
0.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2.

CVE-2023-52155
Software Genérico Web Database
7.2
HIGH
EPSS
0.4%
2023 1 PoC

A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.

CVE-2023-1425
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins

CVE-2023-0277
WC Fields Factory Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-1211
phpipam/phpipam Web Database
7.2
HIGH
EPSS
0.3%
2023 CWE-89 2 PoCs

SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.

CVE-2023-4691
WordPress Online Booking and Scheduling Plugin Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0329
Elementor Website Builder Web Database Windows
7.2
HIGH
EPSS
9.1%
2023 2 PoCs

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

CVE-2023-1408
Video List Manager Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
12.4%
2023 1 PoC

The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-24685
Software Genérico Database
7.2
HIGH
EPSS
0.4%
2023 1 PoC

ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

CVE-2023-21980
MySQL Server Database
7.1
HIGH
EPSS
0.4%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/

CVE-2023-26440
OX App Suite Web Database
7.1
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.

CVE-2023-39980
MXsecurity Series Database
7.1
HIGH
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands.

CVE-2023-21896
Solaris Operating System Database
7.0
HIGH
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-6648
Nipah Virus Testing Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.