16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2007-6202
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2007 1 PoC

SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.

CVE-2014-5249
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2013-3746
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Unspecified vulnerability in the Solaris Cluster component in Oracle and Sun Systems Products Suite 3.2, 3.3, and 4 prior to 4.1 SRU 3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Cluster Infrastructure.

CVE-2013-0404
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 2 PoCs

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Boot.

CVE-2021-25069
Download Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

CVE-2014-8604
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
8.4%
2014 1 PoC

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2013-3050
Software Genérico Database
N/A
UNKNOWN
EPSS
4.2%
2013 2 PoCs

SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product.

CVE-2021-42665
Software Genérico Web Database
N/A
UNKNOWN
EPSS
24.9%
2021 5 PoCs

An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.

CVE-2013-0432
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2013 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient clipboard access premission checks."

CVE-2023-2493
All In One Redirection Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2007-6032
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2007 1 PoC

SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

CVE-2007-6565
Software Genérico Database
N/A
UNKNOWN
EPSS
1.1%
2007 1 PoC

Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary component.

CVE-2014-8375
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2014 2 PoCs

SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.

CVE-2013-0123
Software Genérico Database
N/A
UNKNOWN
EPSS
1.2%
2013 1 PoC

Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pages/pgadmin.asp.

CVE-2021-28970
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.

CVE-2013-0425
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2013 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow

CVE-2023-45381
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform SQL injection via `cp_download_popup().`

CVE-2021-24943
Registrations for the Events Calendar – Event Registration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
55.5%
2021 CWE-89 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVE-2014-8499
Software Genérico Database
N/A
UNKNOWN
EPSS
74.9%
2014 3 PoCs

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.