1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24200
wpDataTables – Tables & Table Charts Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.

CVE-2021-27890
Software Genérico Database
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.

CVE-2021-24769
Permalink Manager Lite Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection

CVE-2021-38706
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.

CVE-2021-37749
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.

CVE-2021-24959
WP Email Users Web Database Windows
N/A
UNKNOWN
EPSS
39.4%
2021 CWE-89 2 PoCs

The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2021-27828
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

CVE-2021-43650
Software Genérico Database
N/A
UNKNOWN
EPSS
1.0%
2021 2 PoCs

WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.

CVE-2021-24827
Asgaros Forum Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

CVE-2021-24631
Unlimited PopUps Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

CVE-2021-41920
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

CVE-2021-24131
Anti-Spam by CleanTalk Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 1 PoC

Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).

CVE-2021-22132
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-522 1 PoC

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2021-44245
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

CVE-2021-41648
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
75.4%
2021 4 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

CVE-2021-22144
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVE-2021-24511
Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.