Fallos del tipo CWE-943

54 resultados
CVE-2020-36195CRITICALSQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-OnEPSS 1.8%CVE-2021-1349MEDIUMCisco SD-WAN vManage Cypher Query Language Injection VulnerabilityEPSS 1.4%CVE-2018-19952If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP SystEPSS 1.3%CVE-2022-36084CRITICALcruddl vulnerable to AQL injection through flexSearchEPSS 1.1%CVE-2020-5257HIGHSort order SQL injection in AdministrateEPSS 0.9%CVE-2021-1481MEDIUMCisco SD-WAN vManage Cypher Query Language Injection VulnerabilityEPSS 0.8%CVE-2021-34712MEDIUMCisco SD-WAN vManage Software Cypher Query Language Injection VulnerabilityEPSS 0.7%CVE-2026-32248CRITICALParse Server: Account takeover via operator injection in authentication data identifierEPSS 0.6%CVE-2026-40351CRITICALFastGPT: NoSQL Injection in loginByPassword leads to Authentication BypassEPSS 0.6%CVE-2026-27886CRITICALStrapi may leak sensitive data via relational filtering due to lack of query sanitizationEPSS 0.6%CVE-2024-28192MEDIUMNoSQL Injection Leading to Authentication Bypass in your_spotifyEPSS 0.6%CVE-2024-31882MEDIUMIBM Db2 denial of serviceEPSS 0.6%CVE-2024-35136MEDIUMIBM Db2 denial of serviceEPSS 0.6%CVE-2025-24787HIGHParameter injection in DB connection URIs leading to local file inclusion in WhoDBEPSS 0.5%CVE-2026-41274CRITICALFlowise: Cypher Injection in GraphCypherQAChainEPSS 0.5%CVE-2026-22558HIGHAn Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access toEPSS 0.5%CVE-2026-25591HIGHNew API has an SQL LIKE Wildcard Injection DoS via Token SearchEPSS 0.5%CVE-2024-4872CRITICALA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attackEPSS 0.5%CVE-2026-25513HIGHFacturaScripts has SQL Injection vulnerability in API ORDER BY ClauseEPSS 0.5%CVE-2026-25514HIGHFacturaScripts has SQL Injection vulnerability in Autocomplete ActionsEPSS 0.5%