1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-32015
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.

CVE-2022-22980
Spring Data MongoDB Web Database
N/A
UNKNOWN
EPSS
83.2%
2022 5 PoCs

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

CVE-2022-0420
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-89 1 PoC

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

CVE-2022-0169
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.2%
2022 CWE-89 2 PoCs

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVE-2022-31296
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.3%
2022 2 PoCs

Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.

CVE-2022-32398
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

CVE-2022-31983
Software Genérico Database
N/A
UNKNOWN
EPSS
45.4%
2022 1 PoC

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.

CVE-2022-27412
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.

CVE-2022-1686
Five Minute Webshop Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection

CVE-2022-1691
Realty Workstation Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-89 2 PoCs

The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection

CVE-2022-36120
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a low/no privilege Blue Prism user account, the attacker can alter the server's settings by abusing the getChartData method, allowing the Blue Prism server to execute any MSSQL stored procedure by name.

CVE-2022-23715
Elastic Cloud Enterprise Web Database Cloud
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-532 1 PoC

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystore

CVE-2022-0479
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.4%
2022 CWE-89 1 PoC

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

CVE-2022-3142
NEX-Forms – Ultimate Form Builder – Contact forms and much more Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2022 CWE-89 3 PoCs

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

CVE-2022-30512
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.8%
2022 2 PoCs

School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.

CVE-2022-25223
Money Transfer Management System Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter.

CVE-2022-32013
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.

CVE-2022-29709
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

CVE-2022-3141
Translate Multilingual sites – TranslatePress Web Database Windows
N/A
UNKNOWN
EPSS
3.9%
2022 CWE-89 4 PoCs

The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.

CVE-2022-26293
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2022 3 PoCs

Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.