1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24554
Paytm – Donation Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-89 2 PoCs

The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

CVE-2021-46427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

CVE-2021-24866
WP Data Access Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion

CVE-2021-24557
M-vSlider Database
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.

CVE-2021-45411
Software Genérico Database
N/A
UNKNOWN
EPSS
3.2%
2021 2 PoCs

In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.

CVE-2021-24772
Stream Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

CVE-2021-29343
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.

CVE-2021-25064
Wow Countdowns – easily create any countdowns, counters and timers Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.

CVE-2021-42662
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 5 PoCs

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.

CVE-2021-45821
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such as usernames and passwords and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-39379
Software Genérico Web Database
N/A
UNKNOWN
EPSS
7.0%
2021 1 PoC

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

CVE-2021-26822
Software Genérico Web Database
N/A
UNKNOWN
EPSS
16.0%
2021 1 PoC

Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.

CVE-2021-26765
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.7%
2021 3 PoCs

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.

CVE-2021-24728
Membership & Content Restriction – Paid Member Subscriptions Web Database Windows
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-89 2 PoCs

The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

CVE-2021-25070
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

CVE-2021-43509
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.

CVE-2021-24130
WP Google Map Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).

CVE-2021-39377
Software Genérico Web Database
N/A
UNKNOWN
EPSS
7.0%
2021 1 PoC

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.

CVE-2021-28925
Software Genérico Web Database
N/A
UNKNOWN
EPSS
47.7%
2021 1 PoC

SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

CVE-2021-35487
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.