16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-38706
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.

CVE-2007-4255
Software Genérico Web Database
N/A
UNKNOWN
EPSS
8.8%
2007 1 PoC

Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function.

CVE-2007-3388
Software Genérico Database
N/A
UNKNOWN
EPSS
13.1%
2007 1 PoC

Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.

CVE-2007-3526
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2007 1 PoC

Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.

CVE-2007-2824
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php.

CVE-2007-4808
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2007 1 PoC

Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the good

CVE-2014-4249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2014 3 PoCs

Unspecified vulnerability in the BI Publisher component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Mobile Service.

CVE-2013-1530
Software Genérico Database
N/A
UNKNOWN
EPSS
0.0%
2013 3 PoCs

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.

CVE-2023-31717
Software Genérico Database
N/A
UNKNOWN
EPSS
30.8%
2023 2 PoCs

A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

CVE-2021-24959
WP Email Users Web Database Windows
N/A
UNKNOWN
EPSS
39.4%
2021 CWE-89 2 PoCs

The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.

CVE-2013-2402
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2013 2 PoCs

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to WorkCenter.

CVE-2023-40748
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

CVE-2013-1408
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2013 1 PoC

Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

CVE-2021-41648
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
75.4%
2021 4 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

CVE-2013-3836
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Unspecified vulnerability in the Oracle Web Cache component in Oracle Fusion Middleware 11.1.1.6 and 11.1.1.7 allows remote authenticated users to affect confidentiality via vectors related to ESI/Partial Page Caching.

CVE-2021-26751
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.

CVE-2007-3000
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.0%
2007 1 PoC

Multiple SQL injection vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to execute arbitrary SQL commands via (1) the iCategoryUnq parameter to G_Display.php or (2) the iSearchID parameter to Search/DisplayResults.php.

CVE-2014-10015
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.1%
2014 1 PoC

SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

CVE-2013-3816
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Unspecified vulnerability in the Oracle Policy Automation component in Oracle Industry Applications 10.2.0, 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Determinations Engine.

CVE-2021-40814
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.