881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-5108
Easy Newsletter Signups Web Database Windows
N/A
UNKNOWN
EPSS
1.3%
2023 1 PoC

The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-2744
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Database Windows
N/A
UNKNOWN
EPSS
28.4%
2023 3 PoCs

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-35811
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the REST API because of missing input validation. Regular user privileges can use used for exploitation. Editions other than Enterprise are also affected.

CVE-2023-46014
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.

CVE-2023-24731
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.

CVE-2023-26325
ReviewX WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

CVE-2023-41636
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.

CVE-2023-38912
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.1%
2023 1 PoC

SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.

CVE-2023-2761
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-46021
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.

CVE-2023-43470
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2023 1 PoC

SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

CVE-2023-36968
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.

CVE-2023-40931
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
88.4%
2023 3 PoCs

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

CVE-2023-38190
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.

CVE-2023-0630
Slimstat Analytics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2023 2 PoCs

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

CVE-2023-5674
WP Mail Log Web Database Windows
N/A
UNKNOWN
EPSS
11.0%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

CVE-2023-21521
AtHoc Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.

CVE-2023-41364
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

CVE-2023-36213
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

CVE-2023-45386
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().'