881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-37772
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.

CVE-2023-28661
WP Popup Banners WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.

CVE-2023-0263
WP Yelp Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-27213
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.

CVE-2023-46022
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.

CVE-2023-46018
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.

CVE-2023-39551
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.

CVE-2023-5645
WP Mail Log Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

CVE-2023-2636
AN_GradeBook Web Database Windows
N/A
UNKNOWN
EPSS
4.6%
2023 3 PoCs

The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber

CVE-2023-22974
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.5%
2023 1 PoC

A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

CVE-2023-6593
Remote Desktop Manager Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.

CVE-2023-46582
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.

CVE-2023-36306
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

CVE-2023-28660
Events Made Easy WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.

CVE-2023-39639
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.

CVE-2023-40989
Software Genérico Database
N/A
UNKNOWN
EPSS
38.7%
2023 1 PoC

SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.

CVE-2023-27207
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

CVE-2023-46584
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.

CVE-2023-38888
Software Genérico Web Database
N/A
UNKNOWN
EPSS
5.0%
2023 1 PoC

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

CVE-2023-37361
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.