16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-3047
Lockcell Database
9.8
CRITICAL
EPSS
8.8%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.This issue affects Lockcell: before 15.

CVE-2019-12989
🔥 KEV Software Genérico Networking Database ⚡ nuclei
9.8
CRITICAL
EPSS
91.5%
2019 2 PoCs

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

CVE-2019-9885
eclass Web Database
9.8
CRITICAL
EPSS
0.6%
2019 CWE-89 1 PoC

eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

CVE-2024-51065
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

CVE-2024-35286
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
63.8%
2024 0 PoCs

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

CVE-2023-27034
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2023 1 PoC

PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

CVE-2022-31061
glpi Database
9.8
CRITICAL
EPSS
45.9%
2022 CWE-89 2 PoCs

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVE-2024-45918
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

CVE-2024-37858
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 2 PoCs

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

CVE-2022-3241
Build App Online Web Database Windows
9.8
CRITICAL
EPSS
4.4%
2022 1 PoC

The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2022-40943
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2022-4118
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop Web Database Windows
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

CVE-2022-4050
JoomSport Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.2%
2022 1 PoC

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-46966
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

CVE-2023-51951
Software Genérico Web Database
9.8
CRITICAL
EPSS
3.5%
2023 2 PoCs

SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.

CVE-2021-2302
Platform Security for Java Web Database
9.8
CRITICAL
EPSS
52.5%
2021 2 PoCs

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-55099
Software Genérico Web Database
9.8
CRITICAL
EPSS
21.0%
2024 2 PoCs

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVE-2024-6159
Push Notification for Post and BuddyPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
9.8%
2024 1 PoC

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2022-1883
camptocamp/terraboard Database ⚡ nuclei
9.6
CRITICAL
EPSS
62.0%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.

CVE-2022-38490
Software Genérico Database
9.6
CRITICAL
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.