1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-34972
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.

CVE-2022-0383
WP Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

CVE-2022-0349
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.5%
2022 CWE-89 1 PoC

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

CVE-2022-0592
MapSVG Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 1 PoC

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

CVE-2022-24571
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.

CVE-2022-27445
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

CVE-2022-26631
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 3 PoCs

Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.

CVE-2022-28512
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

CVE-2022-1006
Advanced Booking Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

CVE-2022-1690
Note Press Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

CVE-2022-28000
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.

CVE-2022-34265
Software Genérico Database
N/A
UNKNOWN
EPSS
92.8%
2022 5 PoCs

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVE-2022-0788
WP Fundraising Donation and Crowdfunding Platform Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.1%
2022 CWE-89 1 PoC

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users

CVE-2022-30469
Software Genérico Database
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

CVE-2022-37062
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite users database and download it. A successful exploit could allow the attacker to extract usernames and hashed passwords. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct

CVE-2022-32405
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4

CVE-2022-31361
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-29006
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.4%
2022 2 PoCs

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

CVE-2022-30510
Software Genérico Web Database
N/A
UNKNOWN
EPSS
23.8%
2022 2 PoCs

School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.

CVE-2022-34006
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITY\SYSTEM, aka NX-I674 (sub-issue 2). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.