881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2023-5640
Article analytics Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

CVE-2023-40852
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.

CVE-2023-3983
Advantech iView Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

CVE-2023-27847
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
73.1%
2023 1 PoC

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

CVE-2023-2493
All In One Redirection Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-43909
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

CVE-2023-2032
Custom 404 Pro Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.

CVE-2023-45381
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform SQL injection via `cp_download_popup().`

CVE-2023-38891
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

CVE-2023-0579
YARPP Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.

CVE-2023-25206
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.

CVE-2023-39650
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.0%
2023 0 PoCs

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

CVE-2023-39675
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

CVE-2023-27214
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.

CVE-2023-37847
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVE-2023-46358
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In the module "Referral and Affiliation Program" (referralbyphone) version 3.5.1 and before from Snegurka for PrestaShop, a guest can perform SQL injection. Method `ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2023-37628
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Online Piggery Management System 1.0 is vulnerable to SQL Injection.

CVE-2023-42284
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.3%
2023 1 PoC

Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.

CVE-2023-26858
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.