16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2013-2445
Software Genérico Database
N/A
UNKNOWN
EPSS
6.7%
2013 2 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "handling of memory allocation errors."

CVE-2021-41492
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

CVE-2014-8306
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.7%
2014 1 PoC

SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter.

CVE-2013-2418
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2021-42224
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.

CVE-2021-41843
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 4 PoCs

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.

CVE-2013-7187
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.1%
2013 2 PoCs

SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2021-43969
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.

CVE-2007-1897
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
5.0%
2007 1 PoC

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

CVE-2007-6557
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2007 1 PoC

Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.

CVE-2013-0445
Software Genérico Database
N/A
UNKNOWN
EPSS
1.6%
2013 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.

CVE-2021-24957
Advanced Page Visit Counter – Advanced WordPress Visit Counter Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection

CVE-2021-22147
Elasticsearch Database
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-732 1 PoC

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVE-2013-5896
Software Genérico Database
N/A
UNKNOWN
EPSS
4.9%
2013 3 PoCs

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect availability via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that com.sun.corba.se and its sub-packages are not included on the restricted package list.

CVE-2021-41947
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

CVE-2021-45814
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

CVE-2014-9558
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.7%
2014 1 PoC

Multiple SQL injection vulnerabilities in SmartCMS v.2.

CVE-2013-0403
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 2 PoCs

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Utility.

CVE-2021-23835
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2021 2 PoCs

An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to be accepting malicious user input without proper sanitization, thus leading to retrieval of backend server sensitive files, e.g., /etc/passwd, SQLite database files, PHP source code, etc.

CVE-2021-24952
Conversios.io – Google Analytics and Google Shopping plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.