1025 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2022-28533
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.

CVE-2022-1688
Note Press Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

CVE-2022-1014
WP Contacts Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.

CVE-2022-40023
Software Genérico Database
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

CVE-2022-36201
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2022 2 PoCs

Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.

CVE-2022-0439
Email Subscribers & Newsletters Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.2%
2022 2 PoCs

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

CVE-2022-32396
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4

CVE-2022-24265
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
23.8%
2022 0 PoCs

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

CVE-2022-28862
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. This is fixed in all recent versions, such as version 26.2.

CVE-2022-38130
Keysight Technologies Sensor Management Server Database ⚡ nuclei
N/A
UNKNOWN
EPSS
74.8%
2022 0 PoCs

The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.

CVE-2022-0657
5 Stars Rating Funnel WordPress Plugin | RRatingg Web Database Windows
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-89 1 PoC

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

CVE-2022-22897
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2022 2 PoCs

A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.

CVE-2022-27992
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.

CVE-2022-24260
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2022 0 PoCs

A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

CVE-2022-1905
Events Made Easy Web Database Windows
N/A
UNKNOWN
EPSS
23.8%
2022 CWE-89 1 PoC

The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2022-1023
Podcast Importer SecondLine Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file

CVE-2022-28110
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

CVE-2022-23320
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

CVE-2022-0411
Asgaros Forum Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection