16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-44921
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2024-2876
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2024 CWE-89 7 PoCs

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-44542
Software Genérico Database
9.8
CRITICAL
EPSS
28.1%
2024 2 PoCs

SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.

CVE-2024-45249
Cavok Database
9.8
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-24142
Software Genérico Database
9.8
CRITICAL
EPSS
10.3%
2024 1 PoC

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

CVE-2025-52021
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization.

CVE-2024-57035
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

CVE-2017-18362
🔥 KEV Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2017 1 PoC

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

CVE-2024-41702
SiberianCMS v5.0.8 Web Database
9.8
CRITICAL
EPSS
0.2%
2024 CWE-89 1 PoC

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2012-0507
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
93.6%
2012 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which

CVE-2025-66438
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(template, doc) via the get_rendered_template() call chain. Although ERPNext wraps Jinja2 in a SandboxedEnvironment, it exposes sensitive functions such as frappe.db.sql through get_safe_globals(). An authenticated attacker with permission to create or modify a Print Format can inject arbitrary Jinja e

CVE-2024-48307
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 1 PoC

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2024-8911
LatePoint Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
30.9%
2024 CWE-89 0 PoCs

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note that changing a WordPress user's password is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. Without this setting enabled, only the pass

CVE-2024-25239
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

CVE-2023-35088
Apache InLong Web Database
9.8
CRITICAL
EPSS
0.6%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8198

CVE-2023-30192
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
41.9%
2023 1 PoC

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

CVE-2025-70149
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

CVE-2024-39907
1Panel Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 CWE-89 0 PoCs

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.