1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-1731
Metasonic Doc WebClient Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.

CVE-2022-27413
Software Genérico Web Database
N/A
UNKNOWN
EPSS
12.0%
2022 1 PoC

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.

CVE-2022-0784
Title Experiments Free Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.9%
2022 CWE-89 1 PoC

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2022-24121
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.

CVE-2022-27104
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.

CVE-2022-32025
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

CVE-2022-31382
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

CVE-2022-29704
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

CVE-2022-32085
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

CVE-2022-31384
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

CVE-2022-31325
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2022 3 PoCs

There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.

CVE-2022-28531
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.

CVE-2022-23865
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter.

CVE-2022-25096
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.

CVE-2022-35299
SAP SQL Anywhere Database
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-121 1 PoC

SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.

CVE-2022-0255
Database Backup for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue

CVE-2022-38812
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2022 1 PoC

AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.

CVE-2022-1685
Five Minute Webshop Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection

CVE-2022-26986
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.

CVE-2022-27382
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.