16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-31056
glpi Database
9.8
CRITICAL
EPSS
5.2%
2022 CWE-89 1 PoC

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.

CVE-2022-44003
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

CVE-2022-3915
Dokan Web Database Windows
9.8
CRITICAL
EPSS
3.2%
2022 1 PoC

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-44015
Software Genérico Database
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.

CVE-2022-38488
Software Genérico Database
9.8
CRITICAL
EPSS
0.9%
2022 2 PoCs

logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.

CVE-2022-39180
College Management System v1.0 Web Database
9.8
CRITICAL
EPSS
0.2%
2022 CWE-89 1 PoC

College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

CVE-2022-38627
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2022 2 PoCs

Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

CVE-2022-21445
🔥 KEV Application Development Framework (ADF) Web Database
9.8
CRITICAL
EPSS
92.0%
2022 4 PoCs

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middlewar

CVE-2022-36193
Software Genérico Database
9.8
CRITICAL
EPSS
2.0%
2022 2 PoCs

SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

CVE-2022-31061
glpi Database
9.8
CRITICAL
EPSS
45.9%
2022 CWE-89 2 PoCs

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVE-2022-3241
Build App Online Web Database Windows
9.8
CRITICAL
EPSS
4.4%
2022 1 PoC

The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2022-46764
TrueConf Server Web Database
9.8
CRITICAL
EPSS
31.5%
2022 CWE-89 1 PoC

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

CVE-2022-21587
🔥 KEV Web Applications Desktop Integrator Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 6 PoCs

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-25148
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
57.8%
2022 CWE-89 1 PoC

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CVE-2022-44290
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
66.4%
2022 0 PoCs

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

CVE-2022-38922
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.

CVE-2022-21306
WebLogic Server Database
9.8
CRITICAL
EPSS
36.9%
2022 2 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-40944
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2022 3 PoCs

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

CVE-2022-4049
WP User Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
66.6%
2022 1 PoC

The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2022-4681
Hide My WP Web Database Windows
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.