1052 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-40353
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.0%
2021 1 PoC

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.

CVE-2021-43008
Software Genérico Database
N/A
UNKNOWN
EPSS
83.5%
2021 1 PoC

Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.

CVE-2021-28295
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.

CVE-2021-27124
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 3 PoCs

SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.

CVE-2021-35975
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)

CVE-2021-24142
301 Redirects - Easy Redirect Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

CVE-2021-28157
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.

CVE-2021-24753
Rich Reviews by Starfish Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

CVE-2021-24461
FAQ Builder AYS Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-28419
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.

CVE-2021-34166
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.

CVE-2021-37291
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2021 1 PoC

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

CVE-2021-24183
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
7.6%
2021 CWE-89 1 PoC

The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

CVE-2021-29004
Software Genérico Database
N/A
UNKNOWN
EPSS
1.6%
2021 3 PoCs

rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.

CVE-2021-41651
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.

CVE-2021-24390
WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.

CVE-2021-24497
Giveaway Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.

CVE-2021-45041
Software Genérico Database
N/A
UNKNOWN
EPSS
13.3%
2021 1 PoC

SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.