1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-31415
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.

CVE-2022-25003
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.

CVE-2022-30927
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable "id" parameter.

CVE-2022-29659
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 3 PoCs

Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

CVE-2022-32311
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.

CVE-2022-0747
Infographic Maker – iList Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.5%
2022 CWE-89 1 PoC

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-27456
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

CVE-2022-25322
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2022 0 PoCs

ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

CVE-2022-37201
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-1800
Export any WordPress data to XML/CSV Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

CVE-2022-1556
StaffList Web Database Windows
N/A
UNKNOWN
EPSS
8.8%
2022 CWE-89 2 PoCs

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

CVE-2022-0658
CommonsBooking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
47.3%
2022 CWE-89 1 PoC

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

CVE-2022-32397
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4

CVE-2022-26632
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.

CVE-2022-0826
WP Video Gallery Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2022 CWE-89 1 PoC

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-29549
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was installed by root) and without integrity checks (e.g., a checksum comparison against known legitimate programs). Also, the vendor recommendation is to install this agent software with root privileges. Thus, privilege escalation is possible on systems where any of these pathnames is controlled by a non-root user. An example is /opt/firebird/bin/isql, where the /opt/firebird directory is often owned by

CVE-2022-1123
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-89 1 PoC

The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.

CVE-2022-32400
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

CVE-2022-32402
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4

CVE-2022-32393
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4