16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-58341
OpenCart Core Database
8.8
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques.

CVE-2025-66437
Software Genérico Database
8.8
HIGH
EPSS
0.1%
2025 1 PoC

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dangerous functions like frappe.db.sql remain accessible via get_safe_globals(). An authenticated attacker with permission to create or modify an Address Template can inject arbitrary Jinja expressions in

CVE-2019-25494
Homey BNB (Airbnb Clone Script) Database
8.8
HIGH
EPSS
0.4%
2019 CWE-89 1 PoC

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel.

CVE-2019-25700
Kados R10 GreenBee Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modify data.

CVE-2023-0234
SiteGround Security Web Database Windows
8.8
HIGH
EPSS
6.7%
2023 1 PoC

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

CVE-2019-3010
🔥 KEV Solaris Operating System Database
8.8
HIGH
EPSS
50.2%
2019 2 PoCs

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C

CVE-2025-15560
WorkTime (on-prem/cloud) Web Database Cloud
8.8
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL statements on the database backend and gain access to sensitive data.

CVE-2023-5412
Image horizontal reel scroll slideshow Web Database Windows
8.8
HIGH
EPSS
9.8%
2023 CWE-89 1 PoC

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2020-12507
moni:tools Database
8.8
HIGH
EPSS
0.7%
2020 CWE-89 1 PoC

In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of integrity and DoS.

CVE-2020-37076
CMSsite Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.

CVE-2019-25489
Homey BNB (Airbnb Clone Script) Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract sensitive database information or cause denial of service.

CVE-2019-25662
ResourceSpace Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database information including usernames and credentials.

CVE-2018-25194
Nominas Web Database
8.8
HIGH
EPSS
0.2%
2018 CWE-22 1 PoC

Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username parameter. Attackers can send POST requests to the login/checklogin.php endpoint with crafted UNION-based SQL injection payloads to extract database information including usernames, database names, and version details.

CVE-2024-11267
JSP Store Locator Web Database Windows
8.8
HIGH
EPSS
1.3%
2024 1 PoC

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

CVE-2023-4776
School Management System Web Database Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

CVE-2019-25460
Ticaret Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time-based SQL injection techniques to extract sensitive database information.

CVE-2018-25173
Rmedia SMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and sensitive database data.

CVE-2019-25543
Netartmedia Real Estate Portal Web Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass authentication, extract sensitive data, or modify database contents.

CVE-2018-25185
Wecodex Restaurant CMS Web Database
8.8
HIGH
EPSS
0.0%
2018 CWE-89 1 PoC

Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind techniques to extract sensitive database information.

CVE-2019-25433
XOOPS CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the gerar_pdf.php endpoint with malicious cid values to extract sensitive database information.