1059 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-27304
pgx Database
9.8
CRITICAL
EPSS
1.9%
2024 CWE-89 2 PoCs

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVE-2024-44349
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2024 2 PoCs

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

CVE-2024-53499
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

CVE-2024-1981
Migration, Backup, Staging – WPvivid Web Database Windows
9.8
CRITICAL
EPSS
2.6%
2024 1 PoC

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-30998
Software Genérico Web Database
9.8
CRITICAL
EPSS
13.3%
2024 1 PoC

SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.

CVE-2024-43360
zoneminder Database ⚡ nuclei
9.8
CRITICAL
EPSS
63.3%
2024 CWE-89 0 PoCs

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

CVE-2024-22901
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

CVE-2024-6265
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
32.9%
2024 CWE-89 0 PoCs

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-38882
Software Genérico Database
9.8
CRITICAL
EPSS
6.6%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.

CVE-2024-28322
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.

CVE-2024-57328
Software Genérico Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.

CVE-2024-57034
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

CVE-2024-30980
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 2 PoCs

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.

CVE-2024-40498
Software Genérico Web Database
9.8
CRITICAL
EPSS
11.8%
2024 1 PoC

SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php

CVE-2024-30985
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

CVE-2024-53480
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

CVE-2024-28595
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.3%
2024 1 PoC

SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

CVE-2024-6847
Chatbot with ChatGPT WordPress Web Database Windows
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

CVE-2024-22611
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

CVE-2024-24095
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.