16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24889
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

CVE-2023-41636
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.

CVE-2021-24463
Image Slider by Ays- Responsive Slider and Carousel Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2007-1163
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.0%
2007 1 PoC

SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.

CVE-2007-4602
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2007 1 PoC

SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2014-4231
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2014 3 PoCs

Unspecified vulnerability in the Siebel Travel & Transportation component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Diary.

CVE-2013-2434
Software Genérico Database
N/A
UNKNOWN
EPSS
1.5%
2013 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2021-45803
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.

CVE-2013-2443
Software Genérico Database
N/A
UNKNOWN
EPSS
3.9%
2013 3 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2452 and CVE-2013-2455. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is due to an incorrect "checking order" within the AccessControlContext class.

CVE-2023-36968
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.

CVE-2021-26762
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2021 3 PoCs

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

CVE-2014-8682
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
76.9%
2014 3 PoCs

Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go.

CVE-2013-0387
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2013 2 PoCs

Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to PeopleCode.

CVE-2021-43035
Software Genérico Database
N/A
UNKNOWN
EPSS
4.0%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account.

CVE-2021-24726
WP Simple Booking Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 2 PoCs

The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue

CVE-2013-5826
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2013 1 PoC

Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3 and 6.3.1 allows remote attackers to affect availability via unknown vectors related to Install / Installation.

CVE-2023-0630
Slimstat Analytics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2023 2 PoCs

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

CVE-2021-24951
LearnPress – WordPress LMS Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

CVE-2007-5521
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.3.3, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS06.

CVE-2014-0383
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.2.0 and 11.1.2.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Identity Console.