1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-24407
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

CVE-2022-28530
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.

CVE-2022-26585
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 1 PoC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

CVE-2022-27452
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.

CVE-2022-37152
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

CVE-2022-1950
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.7%
2022 CWE-89 1 PoC

The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

CVE-2022-0332
moodle Database
N/A
UNKNOWN
EPSS
3.1%
2022 CWE-89 1 PoC

A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

CVE-2022-36669
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2022-1472
Better Find and Replace Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-31383
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

CVE-2022-23305
Apache Log4j 1.x Web Database
N/A
UNKNOWN
EPSS
9.5%
2022 CWE-89 3 PoCs

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with pr

CVE-2022-27670
SAP SQL Anywhere Server Database
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-99 1 PoC

SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use indirect identifiers.

CVE-2022-2559
Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users

CVE-2022-37138
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.

CVE-2022-32007
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.

CVE-2022-26651
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.8-cert14.

CVE-2022-27985
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-27387
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

CVE-2022-27386
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.