16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-37777
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands.

CVE-2024-6926
Viral Signup Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.4%
2024 1 PoC

The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-47926
TCExam Database
9.8
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVE-2024-8503
VICIdial Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2024 CWE-89 3 PoCs

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

CVE-2024-44349
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2024 2 PoCs

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

CVE-2023-34752
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
30.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2024-27304
pgx Database
9.8
CRITICAL
EPSS
1.9%
2024 CWE-89 2 PoCs

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVE-2024-6847
Chatbot with ChatGPT WordPress Web Database Windows
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

CVE-2023-4490
WP Job Portal Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
41.1%
2023 1 PoC

The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2024-44542
Software Genérico Database
9.8
CRITICAL
EPSS
28.1%
2024 2 PoCs

SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.

CVE-2024-50766
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2024-6028
Quiz Maker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2024 CWE-89 2 PoCs

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-57328
Software Genérico Database
9.8
CRITICAL
EPSS
0.0%
2024 1 PoC

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.

CVE-2024-53480
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

CVE-2015-4852
🔥 KEV Software Genérico Web Database
9.8
CRITICAL
EPSS
92.9%
2015 10 PoCs

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVE-2024-34989
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

CVE-2023-24198
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

CVE-2015-2590
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
61.7%
2015 2 PoCs

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

CVE-2015-1427
🔥 KEV Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.3%
2015 9 PoCs

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.