13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2018-25188
Webiness Inventory Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensitive database information including usernames, databases, and version details.

CVE-2018-25185
Wecodex Restaurant CMS Web Database
8.8
HIGH
EPSS
0.0%
2018 CWE-89 1 PoC

Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind techniques to extract sensitive database information.

CVE-2018-4063
🔥 KEV Sierra Wireless Web
8.8
HIGH
EPSS
2.2%
2018 3 PoCs

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2018-25195
Wecodex Hotel CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.

CVE-2018-25199
OOP CMS BLOG Web Database
8.8
HIGH
EPSS
0.2%
2018 CWE-89 1 PoC

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.

CVE-2018-25166
Meneame English Pligg Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to index.php with crafted SQL payloads in the search parameter to extract sensitive database information including usernames, database names, and version details.

CVE-2018-21102
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2018 1 PoC

NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

CVE-2018-25209
OpenBiz Cubi Lite Web Database
8.8
HIGH
EPSS
0.4%
2018 CWE-89 1 PoC

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database information or bypass authentication.

CVE-2018-25183
Shipping System CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login endpoint to authenticate without valid credentials.

CVE-2018-25203
Online Store System CMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind SQL injection payloads in the email field to extract sensitive database information.

CVE-2018-3924
Foxit Web
8.8
HIGH
EPSS
48.3%
2018 1 PoC

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVE-2018-25170
DoceboLMS Web Database
8.8
HIGH
EPSS
0.0%
2018 CWE-352 1 PoC

DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id, idC, and idU parameters. Attackers can send GET requests to the lesson.php endpoint with malicious SQL payloads to extract sensitive database information.

CVE-2018-25300
XATABoost CMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.

CVE-2018-25192
GPS Tracking System Web Database
8.8
HIGH
EPSS
0.3%
2018 CWE-89 1 PoC

GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit crafted POST requests to the login.php endpoint with SQL injection payloads in the username field to gain unauthorized access without valid credentials.

CVE-2022-23642
sourcegraph Web Networking
8.8
HIGH
EPSS
85.3%
2022 CWE-94 3 PoCs

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is

CVE-2022-44019
Software Genérico Web
8.8
HIGH
EPSS
3.6%
2022 2 PoCs

In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.

CVE-2022-40878
Software Genérico Web
8.8
HIGH
EPSS
7.2%
2022 1 PoC

In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).

CVE-2022-22758
Firefox Web
8.8
HIGH
EPSS
0.2%
2022 2 PoCs

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVE-2022-3849
WP User Merger Web Database Windows
8.8
HIGH
EPSS
0.5%
2022 2 PoCs

The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

CVE-2022-46604
Software Genérico Web
8.8
HIGH
EPSS
39.6%
2022 5 PoCs

An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.