1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-32392
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4

CVE-2022-27446
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.

CVE-2022-0190
Ad Invalid Click Protector (AICP) Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-89 1 PoC

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.

CVE-2022-23712
elasticsearch Database
N/A
UNKNOWN
EPSS
3.2%
2022 CWE-754 1 PoC

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVE-2022-34005
Software Genérico Database
N/A
UNKNOWN
EPSS
1.6%
2022 1 PoC

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue 1). NOTE: as of 2022-06-21, the 1.2.1050 release corrects this vulnerability in a new installation, but not in an upgrade installation.

CVE-2022-30518
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.

CVE-2022-31856
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.

CVE-2022-27455
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

CVE-2022-0827
Bestbooks Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.0%
2022 CWE-89 1 PoC

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-23366
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 3 PoCs

HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.

CVE-2022-31978
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
48.2%
2022 0 PoCs

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.

CVE-2022-27434
Software Genérico Database
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.

CVE-2022-1684
CUBE SLIDER Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin

CVE-2022-22735
Simple Quotation Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacks

CVE-2022-24266
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
37.4%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

CVE-2022-27449
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.

CVE-2022-27378
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVE-2022-0817
BadgeOS Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.7%
2022 CWE-89 1 PoC

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-1683
amtyThumb Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement via its shortcode, leading to an SQL injection and is exploitable by any authenticated user (and not just Author+ like the original advisory mention) due to the fact that they can execute shortcodes via an AJAX action

CVE-2022-47532
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.