881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-41014
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

CVE-2023-34756
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVE-2023-30191
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().

CVE-2023-25158
geotools Database
9.8
CRITICAL
EPSS
3.8%
2023 CWE-89 1 PoC

GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters with JDBCDataStore implementations. Users are advised to upgrade to either version 27.4 or to 28.2 to resolve this issue. Users unable to upgrade may disable `encode functions` for PostGIS DataStores or enable `prepared statements` for JDBCDataStores as a partial mitigation.

CVE-2023-4188
instantsoft/icms2 Web Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-6567
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
82.3%
2023 CWE-89 1 PoC

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-35088
Apache InLong Web Database
9.8
CRITICAL
EPSS
0.6%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8198

CVE-2023-51828
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.

CVE-2023-24200
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

CVE-2023-26785
Software Genérico Database
9.8
CRITICAL
EPSS
63.0%
2023 1 PoC

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVE-2023-27742
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.

CVE-2023-37177
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.3%
2023 1 PoC

SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.

CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2023-30092
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2023 2 PoCs

SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.

CVE-2023-1934
PnPSCADA Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential in

CVE-2023-47253
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2023 4 PoCs

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

CVE-2023-48901
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2023 1 PoC

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

CVE-2023-25207
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

CVE-2023-53975
Atom CMS Web Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

CVE-2023-53972
WebTareas Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL injection techniques to extract database information and potentially access sensitive system data.