16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-34751
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

CVE-2023-37777
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands.

CVE-2023-27843
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.

CVE-2023-27034
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2023 1 PoC

PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

CVE-2023-34753
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

CVE-2023-33362
Software Genérico Database
9.8
CRITICAL
EPSS
1.3%
2023 1 PoC

Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.

CVE-2023-49931
Software Genérico Database
9.8
CRITICAL
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

CVE-2023-3490
fossbilling/fossbilling Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-24201
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

CVE-2023-51828
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.

CVE-2023-48901
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2023 1 PoC

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

CVE-2023-23488
Paid Memberships Pro WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.2%
2023 5 PoCs

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CVE-2023-23279
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2023 2 PoCs

Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.

CVE-2023-47253
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2023 4 PoCs

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

CVE-2023-27032
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
40.8%
2023 1 PoC

Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

CVE-2023-39852
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2023 1 PoC

Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that this originates from $_SESSION["userid"]=$_POST["userid"] at line 68 in doctors\doctorlogin.php, where userid under POST is not a session variable controlled by the server.

CVE-2023-23331
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.

CVE-2023-0037
10Web Map Builder for Google Maps Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
65.6%
2023 1 PoC

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2023-30192
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
41.9%
2023 1 PoC

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

CVE-2023-37177
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.3%
2023 1 PoC

SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.