1059 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2024-38882
Software Genérico Database
9.8
CRITICAL
EPSS
6.6%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.

CVE-2024-22611
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-89 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-25897
Software Genérico Web Database
9.8
CRITICAL
EPSS
12.3%
2024 1 PoC

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

CVE-2024-5827
vanna-ai/vanna Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.9%
2024 CWE-89 0 PoCs

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead to command execution or the creation of backdoors.

CVE-2024-24095
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

CVE-2024-57768
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

CVE-2024-25250
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

CVE-2024-35374
Software Genérico Web Database
9.8
CRITICAL
EPSS
8.4%
2024 1 PoC

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

CVE-2024-44659
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

CVE-2024-57328
Software Genérico Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.

CVE-2024-8855
WordPress Auction Plugin Web Database Windows
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks

CVE-2024-28613
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.

CVE-2024-3495
Country State City Dropdown CF7 Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2024 CWE-89 2 PoCs

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-55099
Software Genérico Web Database
9.8
CRITICAL
EPSS
21.0%
2024 2 PoCs

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVE-2024-21082
BI Publisher (formerly XML Publisher) Web Database
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-27746
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.

CVE-2024-2876
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2024 CWE-89 7 PoCs

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-54820
Software Genérico Database
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

CVE-2024-44541
Software Genérico Database
9.8
CRITICAL
EPSS
2.9%
2024 1 PoC

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."