881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-24732
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.

CVE-2023-3435
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

CVE-2023-46023
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive information via the 'status' parameter.

CVE-2023-45376
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`

CVE-2023-36934
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.9%
2023 0 PoCs

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2023-24655
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.

CVE-2023-30415
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

CVE-2023-31717
Software Genérico Database
N/A
UNKNOWN
EPSS
30.8%
2023 2 PoCs

A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

CVE-2023-44047
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.

CVE-2023-40748
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

CVE-2023-37682
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php.

CVE-2023-38870
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

CVE-2023-34581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

CVE-2023-38890
Software Genérico Database
N/A
UNKNOWN
EPSS
5.6%
2023 2 PoCs

Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.

CVE-2023-23315
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2023-31719
Software Genérico Web Database
N/A
UNKNOWN
EPSS
65.5%
2023 2 PoCs

FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

CVE-2023-50070
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

CVE-2023-34659
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2023 0 PoCs

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

CVE-2023-41507
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.