1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-30335
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

CVE-2022-28001
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.

CVE-2022-30352
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.

CVE-2022-32399
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4

CVE-2022-27927
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2022 2 PoCs

A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.

CVE-2022-28033
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
58.4%
2022 0 PoCs

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

CVE-2022-27984
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-37203
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-2754
Ketchup Restaurant Reservations Web Database Windows
N/A
UNKNOWN
EPSS
4.4%
2022 CWE-89 1 PoC

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

CVE-2022-28346
Software Genérico Database
N/A
UNKNOWN
EPSS
2.0%
2022 7 PoCs

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVE-2022-0786
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.2%
2022 CWE-89 1 PoC

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

CVE-2022-34590
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.

CVE-2022-2958
BadgeOS Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-89 1 PoC

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

CVE-2022-32404
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3

CVE-2022-0771
SiteSuperCharger Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

CVE-2022-27385
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVE-2022-0760
Simple Link Directory Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.3%
2022 CWE-89 1 PoC

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-0769
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2022 CWE-89 1 PoC

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CVE-2022-0228
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 CWE-89 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

CVE-2022-2593
Better Search Replace Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks