16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-0234
SiteGround Security Web Database Windows
8.8
HIGH
EPSS
6.7%
2023 1 PoC

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

CVE-2020-36077
Software Genérico Web Database
8.8
HIGH
EPSS
2.4%
2020 1 PoC

SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the customer parameter of the orderadd.php file

CVE-2023-5412
Image horizontal reel scroll slideshow Web Database Windows
8.8
HIGH
EPSS
9.8%
2023 CWE-89 1 PoC

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2020-37141
AMSS++ Web Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.

CVE-2019-25526
Inout EasyRooms Ultimate Edition Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the location parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads in the location field to extract sensitive data or modify database contents.

CVE-2019-25537
Netartmedia Event Portal Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL payloads in the Email field to extract sensitive database information.

CVE-2021-47846
Digital Crime Report Management System Database
8.8
HIGH
EPSS
0.1%
2021 CWE-89 1 PoC

Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police, incharge, user, and HQ login endpoints.

CVE-2025-46109
Software Genérico Web Database
8.8
HIGH
EPSS
0.4%
2025 1 PoC

SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request

CVE-2023-4776
School Management System Web Database Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

CVE-2019-25366
microASP (Portal+) CMS Web Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to extract sensitive database information like the current database name.

CVE-2019-25516
Hazir Haber Sitesi Scripti Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gallery_id parameter. Attackers can send GET requests to gallery.php with malicious gallery_id values using UNION-based SQL injection to extract sensitive database information.

CVE-2019-25684
OpenDocMan Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.

CVE-2022-3641
Remote Desktop Manager Database Cloud
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.

CVE-2020-37057
Online-Exam-System Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

CVE-2012-0158
🔥 KEV Software Genérico Database
8.8
HIGH
EPSS
94.3%
2012 3 PoCs

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in

CVE-2019-25698
Kados R10 GreenBee Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive database information.

CVE-2023-28659
Waiting: One-click Countdowns WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.1%
2023 1 PoC

The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.

CVE-2023-2719
SupportCandy Web Database Windows
8.8
HIGH
EPSS
4.3%
2023 2 PoCs

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

CVE-2022-3848
WP User Merger Web Database Windows
8.8
HIGH
EPSS
0.5%
2022 2 PoCs

The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

CVE-2019-25439
NoviSmart CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.