1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-32024
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

CVE-2022-32088
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVE-2022-36635
Software Genérico Database
N/A
UNKNOWN
EPSS
2.1%
2022 1 PoC

ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

CVE-2022-32094
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.8%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.

CVE-2022-29650
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

CVE-2022-28452
Software Genérico Database
N/A
UNKNOWN
EPSS
2.0%
2022 1 PoC

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVE-2022-24263
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.9%
2022 3 PoCs

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

CVE-2022-29009
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 2 PoCs

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

CVE-2022-2840
Zephyr Project Manager Web Database Windows
N/A
UNKNOWN
EPSS
3.8%
2022 CWE-89 2 PoCs

The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections

CVE-2022-32403
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4

CVE-2022-0694
Advanced Booking Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVE-2022-2269
Website File Changes Monitor Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-89 1 PoC

The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection

CVE-2022-32022
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

CVE-2022-1182
Visual Slide Box Builder Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections

CVE-2022-24223
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
27.5%
2022 1 PoC

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

CVE-2022-24264
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
23.7%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

CVE-2022-32391
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

CVE-2022-0948
Order Listener for WooCommerce – Play Sounds Instantly on New Orders Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.4%
2022 CWE-89 1 PoC

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

CVE-2022-0846
SpeakOut! Email Petitions Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2022 CWE-89 1 PoC

The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-48149
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.