16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2019-2880
Retail Store Inventory Management Web Database
8.8
HIGH
EPSS
1.5%
2019 1 PoC

Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security). The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Store Inventory Management. Successful attacks of this vulnerability can result in takeover of Oracle Retail Store Inventory Management. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-29842
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2023 3 PoCs

ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

CVE-2024-35584
Software Genérico Web Database ⚡ nuclei
8.8
HIGH
EPSS
82.5%
2024 1 PoC

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.

CVE-2019-25668
News Website Script Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information.

CVE-2019-25491
Homey BNB (Airbnb Clone Script) Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to extract sensitive database information.

CVE-2024-3217
WP Directory Kit Web Database Windows
8.8
HIGH
EPSS
52.9%
2024 CWE-89 1 PoC

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2019-25535
Netartmedia Php Dating Site Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive database information.

CVE-2023-23490
Survey Maker WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.4%
2023 1 PoC

The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.

CVE-2019-25530
uHotelBooking System Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection techniques to extract sensitive database information.

CVE-2024-21067
Enterprise Manager Base Platform Database
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Or

CVE-2019-25432
Part-DB Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized access to the application.

CVE-2024-5793
Houzez Theme - Functionality Web Database Windows
8.8
HIGH
EPSS
0.7%
2024 CWE-89 1 PoC

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-36597
Software Genérico Web Database
8.8
HIGH
EPSS
87.0%
2024 1 PoC

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

CVE-2023-28663
Formidable PRO2PDF WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
0.8%
2023 1 PoC

The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.

CVE-2025-52914
Software Genérico Database
8.8
HIGH
EPSS
0.1%
2025 1 PoC

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary SQL database commands.

CVE-2024-37765
Software Genérico Database
8.8
HIGH
EPSS
11.1%
2024 1 PoC

Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

CVE-2024-27299
phpMyFAQ Web Database
8.8
HIGH
EPSS
2.1%
2024 CWE-89 1 PoC

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the the "Add News" functionality due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some cases, even achieve RCE. The vulnerable field lies in the `authorEmail` field which uses PHP's `FILTER_VALIDATE_EMAIL` filter. This filter is insufficient in protecting against SQL injection attacks and should

CVE-2021-47902
Testa Online Test Management System Database
8.8
HIGH
EPSS
0.1%
2021 CWE-89 1 PoC

Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data.

CVE-2024-55656
RedisBloom Web Database
8.8
HIGH
EPSS
13.1%
2024 CWE-190 1 PoC

RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. The integer overflow vulnerability allows an attacker (a redis client which knows the password) to allocate memory in the heap lesser than the required memory due to wraparound. Then read and write can be performed beyond this allocated memory, leading to info leak and OOB write. The integer overflow is in CMS.INITBYDIM command, which initialize a Count-Min Sketch to dimensions specified by user. It accepts two values (width and depth) and

CVE-2019-25533
Netartmedia PHP Business Directory Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract sensitive database information or bypass authentication.