1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-23837
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious user input without proper sanitization, thus leading to SQL injection. Database related information can be successfully retrieved.

CVE-2021-36748
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2021 2 PoCs

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

CVE-2021-22134
Elasticsearch Database
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-200 1 PoC

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVE-2021-24860
BSK PDF Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

CVE-2021-24553
Timeline Calendar Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 2 PoCs

The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

CVE-2021-24360
Yes/No Chart Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks

CVE-2021-43481
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

CVE-2021-44653
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.

CVE-2021-24149
Modern Events Calendar Lite Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

CVE-2021-24186
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

CVE-2021-25054
WPcalc – create any online calculators Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

CVE-2021-24741
Support Board Web Database Windows
N/A
UNKNOWN
EPSS
58.3%
2021 CWE-89 5 PoCs

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

CVE-2021-24580
Side Menu Lite - add sticky fixed buttons Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

CVE-2021-24459
Survey Maker Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-24392
WordPress Membership SwiftCloud.io Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-24143
AccessPress Social Icons Database
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

CVE-2021-44097
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.

CVE-2021-43701
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.

CVE-2021-27973
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

CVE-2021-31816
Octopus Server Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.