1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-29652
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.

CVE-2022-0887
Easy Social Icons Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

CVE-2022-28961
Software Genérico Database
N/A
UNKNOWN
EPSS
1.2%
2022 1 PoC

Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.

CVE-2022-32089
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVE-2022-0267
AdRotate – Ad manager & AdSense Ads Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

CVE-2022-0412
TI WooCommerce Wishlist Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2022 CWE-89 2 PoCs

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

CVE-2022-0739
BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin Web Database Windows
N/A
UNKNOWN
EPSS
69.9%
2022 CWE-89 10 PoCs

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

CVE-2022-24956
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.

CVE-2022-35193
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

CVE-2022-32401
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4

CVE-2022-1057
Pricing Deals for WooCommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.7%
2022 CWE-89 1 PoC

The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

CVE-2022-31976
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.6%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.

CVE-2022-23911
Testimonial WordPress Plugin – AP Custom Testimonial Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

CVE-2022-27448
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

CVE-2022-32394
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3

CVE-2022-0434
Page View Count Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2022 CWE-89 1 PoC

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

CVE-2022-0783
Multiple Shipping Address Woocommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.5%
2022 CWE-89 1 PoC

The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

CVE-2022-38637
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

CVE-2022-28962
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.

CVE-2022-32028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.