881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-46581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.

CVE-2023-27205
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

CVE-2023-32422
macOS Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

This issue was addressed by adding additional SQLite logging restrictions. This issue is fixed in iOS 16.5 and iPadOS 16.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences.

CVE-2023-2601
wpbrutalai Web Database Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

CVE-2023-47261
Software Genérico Database
N/A
UNKNOWN
EPSS
2.7%
2023 1 PoC

Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.

CVE-2023-36311
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

CVE-2023-40749
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

CVE-2023-39641
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent().

CVE-2023-48016
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.

CVE-2023-36118
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.

CVE-2023-40121
Android Database
N/A
UNKNOWN
EPSS
0.1%
2023 4 PoCs

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-45375
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.8%
2023 1 PoC

In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().`

CVE-2023-26959
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.

CVE-2023-41387
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.

CVE-2023-46024
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

CVE-2023-2592
FormCraft Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2023-5640
Article analytics Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

CVE-2023-40852
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.

CVE-2023-3983
Advantech iView Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.