1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24861
Quotes Collection Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

CVE-2021-37538
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2021 1 PoC

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

CVE-2021-43506
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

CVE-2021-43091
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.

CVE-2021-31817
Octopus Server Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

CVE-2021-42668
Software Genérico Web Database
N/A
UNKNOWN
EPSS
29.0%
2021 5 PoCs

A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-24393
Comment Highlighter Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-3110
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.9%
2021 3 PoCs

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

CVE-2021-3018
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.3%
2021 2 PoCs

ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.

CVE-2021-24862
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 CWE-89 2 PoCs

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVE-2021-38574
Software Genérico Database
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.

CVE-2021-43036
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

CVE-2021-44098
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVE-2021-24181
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-89 1 PoC

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

CVE-2021-45811
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

CVE-2021-26904
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

LMA ISIDA Retriever 5.2 allows SQL Injection.

CVE-2021-43510
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2021 2 PoCs

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

CVE-2021-24628
Wow Forms – create any form with custom style Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-29378
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.

CVE-2021-24550
Broken Link Manager Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue