1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24402
WP iCommerce – the first interactive ecommerce for wordpress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

CVE-2021-37371
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2021 3 PoCs

Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.

CVE-2021-24754
MainWP Child Reports Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue

CVE-2021-43969
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.

CVE-2021-36351
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.

CVE-2021-37807
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

CVE-2021-24957
Advanced Page Visit Counter – Advanced WordPress Visit Counter Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection

CVE-2021-24465
Meow Gallery (+ Gallery Block) Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.

CVE-2021-22147
Elasticsearch Database
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-732 1 PoC

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVE-2021-31856
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2021 1 PoC

A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

CVE-2021-25045
Asgaros Forum Web Database Windows
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue

CVE-2021-41947
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

CVE-2021-26754
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.1%
2021 1 PoC

wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.

CVE-2021-24398
RESPONSIVE 3D SLIDER Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.

CVE-2021-41695
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .

CVE-2021-45814
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

CVE-2021-39378
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.3%
2021 1 PoC

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.

CVE-2021-23835
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2021 2 PoCs

An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to be accepting malicious user input without proper sanitization, thus leading to retrieval of backend server sensitive files, e.g., /etc/passwd, SQLite database files, PHP source code, etc.

CVE-2021-41460
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.7%
2021 0 PoCs

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

CVE-2021-24952
Conversios.io – Google Analytics and Google Shopping plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.