16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-43361
HBYS Database
9.9
CRITICAL
EPSS
0.3%
2021 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.

CVE-2021-35683
Hyperion Essbase Administration Services Web Database
9.9
CRITICAL
EPSS
1.5%
2021 1 PoC

Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported version that is affected is Prior to 11.1.2.4.047. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase Administration Services. While the vulnerability is in Oracle Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Essbase Administration Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Int

CVE-2021-43609
Software Genérico Database
9.9
CRITICAL
EPSS
3.7%
2021 2 PoCs

An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.

CVE-2021-21465
SAP Business Warehouse Database
9.9
CRITICAL
EPSS
1.4%
2021 2 PoCs

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

CVE-2024-27956
Automatic Database ⚡ nuclei
9.9
CRITICAL
EPSS
93.8%
2024 CWE-89 17 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

CVE-2024-21010
Hospitality Simphony Web Database
9.9
CRITICAL
EPSS
1.0%
2024 1 PoC

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality,

CVE-2024-42327
Zabbix Web Database
9.9
CRITICAL
EPSS
91.4%
2024 CWE-89 9 PoCs

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

CVE-2024-36393
SysAid Database
9.9
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-20997
Hospitality Simphony Web Database
9.9
CRITICAL
EPSS
1.1%
2024 1 PoC

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality,

CVE-2023-0016
SAP BPC MS 10.0 Database
9.9
CRITICAL
EPSS
0.5%
2023 CWE-89 1 PoC

SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.

CVE-2023-39424
IRM Next Generation Database Windows
9.9
CRITICAL
EPSS
0.4%
2023 CWE-74 1 PoC

A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. 

CVE-2023-26864
Software Genérico Database
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.

CVE-2023-34752
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
30.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2023-39852
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2023 1 PoC

Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that this originates from $_SESSION["userid"]=$_POST["userid"] at line 68 in doctors\doctorlogin.php, where userid under POST is not a session variable controlled by the server.

CVE-2023-50578
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
31.7%
2023 1 PoC

Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.

CVE-2023-50027
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.

CVE-2023-34754
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
14.9%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

CVE-2023-46954
Software Genérico Database
9.8
CRITICAL
EPSS
3.9%
2023 1 PoC

SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

CVE-2015-4852
🔥 KEV Software Genérico Web Database
9.8
CRITICAL
EPSS
92.9%
2015 10 PoCs

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVE-2023-29985
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.