1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-26751
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.

CVE-2021-24626
Chameleon CSS Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-89 2 PoCs

The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL Injection

CVE-2021-24575
School Management System – WPSchoolPress Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

CVE-2021-27928
Software Genérico Database
N/A
UNKNOWN
EPSS
48.9%
2021 5 PoCs

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.

CVE-2021-44249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.

CVE-2021-40814
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.

CVE-2021-42077
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

CVE-2021-26935
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.

CVE-2021-30175
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
60.5%
2021 0 PoCs

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

CVE-2021-41492
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

CVE-2021-22146
Software Genérico Web Database Cloud
N/A
UNKNOWN
EPSS
29.9%
2021 2 PoCs

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVE-2021-24285
Car Seller - Auto Classifieds Script Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2021 CWE-89 1 PoC

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

CVE-2021-24931
Secure Copy Content Protection and Content Locking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.2%
2021 CWE-89 2 PoCs

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CVE-2021-42224
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.

CVE-2021-27316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

CVE-2021-44095
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.

CVE-2021-26201
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.

CVE-2021-25076
WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
52.3%
2021 CWE-89 5 PoCs

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

CVE-2021-41843
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 4 PoCs

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.

CVE-2021-24898
Editable Table Simple Fast FrontEnd From Sql tables Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed