881 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-53982
PMB Web Database
9.3
CRITICAL
EPSS
0.0%
2023 CWE-89 1 PoC

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.

CVE-2023-53960
Impact/Pulse/First Web Database
9.3
CRITICAL
EPSS
0.3%
2023 CWE-89 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.

CVE-2023-32590
Subscribe to Category Database ⚡ nuclei
9.3
CRITICAL
EPSS
19.3%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.

CVE-2023-53975
Atom CMS Web Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

CVE-2023-50839
JS Help Desk – Best Help Desk & Support Plugin Database ⚡ nuclei
9.3
CRITICAL
EPSS
16.3%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.

CVE-2023-28787
Quiz And Survey Master Database ⚡ nuclei
9.3
CRITICAL
EPSS
32.1%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

CVE-2023-48788
🔥 KEV FortiClientEMS Networking Database
9.3
CRITICAL
EPSS
94.1%
2023 CWE-89 5 PoCs

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2023-23459
Priority for Windows Database Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-89 1 PoC

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2023-36645
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

CVE-2023-21975
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Customers Plugin, attacks may significantly impact additional products (scope change). Successful attac

CVE-2023-21974
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calendar Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Team Calendar Plugin, attacks may significantly impact additional products (scope change).

CVE-2023-24652
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.

CVE-2023-28659
Waiting: One-click Countdowns WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.1%
2023 1 PoC

The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.

CVE-2023-28663
Formidable PRO2PDF WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
0.8%
2023 1 PoC

The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.

CVE-2023-4776
School Management System Web Database Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

CVE-2023-54333
Social-Share-Buttons Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted POST requests with malicious SQL payloads to retrieve and potentially steal entire database contents.

CVE-2023-39378
SiberianCMS Web Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user

CVE-2023-0955
WP Statistics Web Database Windows
8.8
HIGH
EPSS
1.5%
2023 1 PoC

The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.

CVE-2023-49548
Software Genérico Web Database
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

CVE-2023-26217
TIBCO EBX Add-ons Database Windows
8.8
HIGH
EPSS
0.2%
2023 CWE-89 1 PoC

The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0.