881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-27210
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.

CVE-2023-42406
Software Genérico Web Database
N/A
UNKNOWN
EPSS
23.3%
2023 1 PoC

SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.

CVE-2023-39642
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::display().

CVE-2023-46017
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.

CVE-2023-5652
WP Hotel Booking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.6%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

CVE-2023-35708
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
75.6%
2023 0 PoCs

In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.

CVE-2023-47800
Software Genérico Database
N/A
UNKNOWN
EPSS
3.7%
2023 1 PoC

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.

CVE-2023-24730
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.

CVE-2023-0631
Paid Memberships Pro Web Database Windows
N/A
UNKNOWN
EPSS
74.0%
2023 1 PoC

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

CVE-2023-40933
Software Genérico Database
N/A
UNKNOWN
EPSS
18.1%
2023 1 PoC

A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

CVE-2023-36940
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.

CVE-2023-43469
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

CVE-2023-34635
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

CVE-2023-47326
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.

CVE-2023-43468
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.

CVE-2023-37165
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2023 1 PoC

Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.

CVE-2023-41640
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a crafted SQL query.

CVE-2023-43144
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.8%
2023 1 PoC

Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

CVE-2023-46581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.

CVE-2023-27205
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.