881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-31714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.

CVE-2023-38992
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
64.1%
2023 0 PoCs

jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

CVE-2023-24788
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2023 3 PoCs

NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.

CVE-2023-7047
Remote Desktop Manager Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.

CVE-2023-36936
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.

CVE-2023-24728
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.

CVE-2023-39121
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2023 0 PoCs

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

CVE-2023-23162
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

CVE-2023-24729
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.

CVE-2023-27204
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

CVE-2023-48925
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

CVE-2023-48084
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2023 2 PoCs

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

CVE-2023-46025
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.

CVE-2023-36941
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.

CVE-2023-39643
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().

CVE-2023-37689
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.

CVE-2023-47445
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

CVE-2023-42283
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.7%
2023 1 PoC

Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.

CVE-2023-2482
Responsive CSS EDITOR Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.

CVE-2023-36942
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.