16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-29168
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2020 1 PoC

SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.

CVE-2020-24600
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2020 2 PoCs

Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

CVE-2020-14841
WebLogic Server Database
9.8
CRITICAL
EPSS
13.5%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-2733
JD Edwards EnterpriseOne Tools Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
88.9%
2020 2 PoCs

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2016-3427
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
93.9%
2016 4 PoCs

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CVE-2016-8735
🔥 KEV Apache Tomcat Web Database
9.8
CRITICAL
EPSS
93.9%
2016 5 PoCs

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CVE-2018-2628
🔥 KEV WebLogic Server Database
9.8
CRITICAL
EPSS
94.4%
2018 26 PoCs

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2018-7841
🔥 KEV U.motion Builder software version 1.3.4 Database ⚡ nuclei
9.8
CRITICAL
EPSS
54.7%
2018 2 PoCs

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

CVE-2010-0840
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
92.1%
2010 7 PoCs

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted cla

CVE-2011-3544
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
92.5%
2011 2 PoCs

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

CVE-2022-35156
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 2 PoCs

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

CVE-2022-46071
Software Genérico DevOps Database ⚡ nuclei
9.8
CRITICAL
EPSS
79.2%
2022 2 PoCs

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

CVE-2022-41403
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.

CVE-2022-25149
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.3%
2022 CWE-89 0 PoCs

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CVE-2022-46966
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

CVE-2022-38923
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.

CVE-2022-4059
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
56.6%
2022 1 PoC

The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-44151
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

CVE-2022-43213
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.