16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-42670
Software Genérico Web Database
N/A
UNKNOWN
EPSS
58.0%
2021 3 PoCs

A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2014-6490
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.7%
2014 1 PoC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB server user component.

CVE-2013-0580
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the authentication of arbitrary users.

CVE-2021-44593
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.4%
2021 4 PoCs

Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.

CVE-2021-24397
MicroCopy Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-44521
Apache Cassandra Web Database
N/A
UNKNOWN
EPSS
91.0%
2021 CWE-94 3 PoCs

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.

CVE-2013-5858
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2015-0370.

CVE-2023-43470
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2023 1 PoC

SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

CVE-2021-24507
Astra Pro Addon Web Database Windows
N/A
UNKNOWN
EPSS
44.2%
2021 CWE-89 2 PoCs

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

CVE-2014-2487
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.1%
2014 3 PoCs

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-4261.

CVE-2013-0397
Software Genérico Database
N/A
UNKNOWN
EPSS
29.9%
2013 2 PoCs

Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Diagnostics.

CVE-2013-2382
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 2 PoCs

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.

CVE-2023-21521
AtHoc Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.

CVE-2007-5485
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2007 1 PoC

SQL injection vulnerability in index.php in the mg2 1.0 module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the album parameter.

CVE-2007-1816
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.

CVE-2007-3881
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2007 1 PoC

SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

CVE-2014-4224
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2014 3 PoCs

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows local users to affect availability via unknown vectors related to sockfs.

CVE-2013-1532
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2013 3 PoCs

Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Information Schema.

CVE-2023-42406
Software Genérico Web Database
N/A
UNKNOWN
EPSS
23.3%
2023 1 PoC

SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.

CVE-2013-0366
Software Genérico Database
N/A
UNKNOWN
EPSS
3.0%
2013 2 PoCs

Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0361.