751 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2025-64081
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter.

CVE-2025-65133
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 2 PoCs

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information.

CVE-2025-70892
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

CVE-2025-57529
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could lead to unauthorized data access

CVE-2025-5329
Delta Course Automation Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection.This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-4578
File Provider Web Database Windows
9.8
CRITICAL
EPSS
0.7%
2025 2 PoCs

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2025-61246
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

CVE-2025-52021
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization.

CVE-2025-61882
🔥 KEV Oracle Concurrent Processing Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2025 11 PoCs

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-65354
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.

CVE-2025-66440
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the to_posting_date parameter, which is directly interpolated into the query without proper sanitization or parameter binding.

CVE-2025-12463
G-Cam Web Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.

CVE-2025-61757
🔥 KEV Identity Manager Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
87.8%
2025 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-25763
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

CVE-2025-61548
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This vulnerability allows remote attackers to execute arbitrary SQL commands

CVE-2025-29085
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
22.6%
2025 0 PoCs

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

CVE-2025-4688
SINAV.LINK Exam Result Module Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection.This issue affects SINAV.LINK Exam Result Module: before 1.2.

CVE-2025-70152
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.

CVE-2025-25257
🔥 KEV FortiWeb Web Networking Database ⚡ nuclei
9.6
CRITICAL
EPSS
22.1%
2025 CWE-89 13 PoCs

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVE-2025-24490
Mattermost Database
9.6
CRITICAL
EPSS
0.5%
2025 CWE-89 1 PoC

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.