16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-8503
VICIdial Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2024 CWE-89 3 PoCs

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

CVE-2024-4547
DIAEnergie Database
9.8
CRITICAL
EPSS
0.9%
2024 CWE-20 1 PoC

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

CVE-2024-50766
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

CVE-2025-61757
🔥 KEV Identity Manager Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
87.8%
2025 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-57768
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

CVE-2023-50027
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.

CVE-2024-39907
1Panel Database ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 CWE-89 0 PoCs

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to upgrade. There are no known workarounds for these issues.

CVE-2023-21890
Communications Converged Application Server Database
9.8
CRITICAL
EPSS
2.8%
2023 1 PoC

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Communications Converged Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:

CVE-2024-36681
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.

CVE-2025-25763
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

CVE-2023-23488
Paid Memberships Pro WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.2%
2023 5 PoCs

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CVE-2023-41014
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

CVE-2023-1934
PnPSCADA Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential in

CVE-2023-29863
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 2 PoCs

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

CVE-2024-7456
lunary-ai/lunary Web Database
9.8
CRITICAL
EPSS
29.3%
2024 CWE-89 1 PoC

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

CVE-2024-44812
Software Genérico Web Database
9.8
CRITICAL
EPSS
18.7%
2024 1 PoC

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

CVE-2024-24095
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

CVE-2023-27034
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2023 1 PoC

PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

CVE-2023-29809
Software Genérico Database
9.8
CRITICAL
EPSS
2.9%
2023 3 PoCs

SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.

CVE-2024-6809
Simple Video Directory Web Database Windows
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.