751 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2025-4578
File Provider Web Database Windows
9.8
CRITICAL
EPSS
0.7%
2025 2 PoCs

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2025-65133
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 2 PoCs

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information.

CVE-2025-32814
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
32.1%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

CVE-2025-22953
Software Genérico Database
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.

CVE-2025-61246
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

CVE-2025-65358
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

CVE-2025-50341
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.

CVE-2025-66439
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the from_posting_date parameter, which is directly interpolated into the query without proper sanitization or parameter binding.

CVE-2025-66944
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

CVE-2025-64081
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter.

CVE-2025-8868
Chef Automate Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.3%
2025 CWE-200 0 PoCs

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

CVE-2025-26198
Software Genérico Web Database Cloud
9.8
CRITICAL
EPSS
1.0%
2025 2 PoCs

CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and bypass authentication, gaining unauthorized administrative access. The vulnerability is triggered when an attacker supplies specially crafted input in the username field, such as ' OR '1'='1, leading to complete compromise of the login mechanism and potential exposure of sensitive bac

CVE-2025-61882
🔥 KEV Oracle Concurrent Processing Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2025 11 PoCs

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-69633
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions).

CVE-2025-9697
Ajax WooSearch Web Database Windows
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2025-2812
Ticket Sales Automation Database
9.8
CRITICAL
EPSS
0.2%
2025 CWE-89 2 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).

CVE-2025-52021
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization.

CVE-2025-60736
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

CVE-2025-12463
G-Cam Web Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.

CVE-2025-46179
Software Genérico Web Database Cloud
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries.