16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2019-2964
Java Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified

CVE-2007-5887
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2007 1 PoC

SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2014-6546
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2014 1 PoC

Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2013-5835
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2013 1 PoC

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Open_UI.

CVE-2021-38727
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items

CVE-2013-5778
Software Genérico Database
N/A
UNKNOWN
EPSS
1.7%
2013 4 PoCs

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, 6u60 and earlier, 5.0u51 and earlier, and Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.

CVE-2023-2032
Custom 404 Pro Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.

CVE-2021-34165
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.

CVE-2014-10038
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.0%
2014 1 PoC

SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.

CVE-2013-5878
Software Genérico Database
N/A
UNKNOWN
EPSS
4.5%
2013 3 PoCs

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the Security component does not properly handle null XML namespace (xmlns) attributes during XML document canonicalization, which allows attackers to escape the sandbox.

CVE-2021-24847
SEO Redirection Plugin – 301 Redirect Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

CVE-2013-1505
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2013 2 PoCs

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BASE.

CVE-2021-24575
School Management System – WPSchoolPress Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

CVE-2021-46427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

CVE-2007-2247
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2007 1 PoC

SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

CVE-2007-2673
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2007 1 PoC

SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php.

CVE-2007-0224
Software Genérico Database
N/A
UNKNOWN
EPSS
1.1%
2007 1 PoC

SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.

CVE-2014-0410
Software Genérico Database
N/A
UNKNOWN
EPSS
5.4%
2014 2 PoCs

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

CVE-2013-2455
Software Genérico Database
N/A
UNKNOWN
EPSS
3.9%
2013 3 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2452. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect access checks by the (1) getEnclosingClass, (2) getEnclosingMethod, and (3) getEnclosingConstructor me

CVE-2021-24345
Sendit WP Newsletter Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.