1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24492
Handsome Testimonials & Reviews Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 2 PoCs

The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.

CVE-2021-37593
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.

CVE-2021-42580
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.8%
2021 3 PoCs

Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.

CVE-2021-24606
Availability Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+

CVE-2021-41647
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 3 PoCs

An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

CVE-2021-37364
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The applic

CVE-2021-45802
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

CVE-2021-42633
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.

CVE-2021-24864
WP Cloudy, weather plugin Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

CVE-2021-24835
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks

CVE-2021-24521
Side Menu Lite – add sticky fixed buttons Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-89 1 PoC

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

CVE-2021-43094
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.

CVE-2021-22145
Elasticsearch Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2021 CWE-200 3 PoCs

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVE-2021-41965
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed.

CVE-2021-24704
Orange Form Web Database Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-89 1 PoC

In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF protection, it is actually exploitable and could allow attackers to make a logged in admin delete arbitrary posts for example

CVE-2021-25114
Paid Memberships Pro Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2021 CWE-89 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVE-2021-20227
sqlite Database
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-416 3 PoCs

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

CVE-2021-44096
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.

CVE-2021-32051
Software Genérico Database
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.

CVE-2021-44280
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2021 4 PoCs

attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.