16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2013-2421
Software Genérico Database
N/A
UNKNOWN
EPSS
25.4%
2013 2 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect MethodHandle lookups, which allows remote attackers to bypass Java sandbox restrictions.

CVE-2021-24141
Advanced Database Cleaner Database
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.

CVE-2007-2889
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2007 1 PoC

SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.

CVE-2014-2421
Software Genérico Database
N/A
UNKNOWN
EPSS
7.4%
2014 2 PoCs

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2013-3763
Software Genérico Database
N/A
UNKNOWN
EPSS
72.2%
2013 1 PoC

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764.

CVE-2021-40247
Software Genérico Database
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.

CVE-2013-1547
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 2 PoCs

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows remote authenticated users to affect integrity via vectors related to BASE.

CVE-2021-42325
Software Genérico Web Database
N/A
UNKNOWN
EPSS
5.5%
2021 3 PoCs

Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

CVE-2021-24627
G Auto-Hyperlink Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-89 2 PoCs

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

CVE-2014-3997
Software Genérico Database
N/A
UNKNOWN
EPSS
1.3%
2014 2 PoCs

SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.

CVE-2013-5834
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Unspecified vulnerability in Oracle Solaris 8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ps.

CVE-2021-28969
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3. NOTE: this is different from CVE-2020-25034 and affects newer versions of the software.

CVE-2013-2018
BOINC Database
N/A
UNKNOWN
EPSS
0.6%
2013 1 PoC

Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2021-24915
Contest Gallery – Photo Contest Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.6%
2021 CWE-89 1 PoC

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

CVE-2007-2773
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2007 1 PoC

SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter.

CVE-2007-1439
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.6%
2007 2 PoCs

PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.

CVE-2014-4873
Software Genérico Database
N/A
UNKNOWN
EPSS
4.9%
2014 1 PoC

SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.

CVE-2013-5866
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Unspecified vulnerability in Oracle Solaris 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

CVE-2013-3830
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2013 1 PoC

Unspecified vulnerability in the Hyperion Strategic Finance component in Oracle Hyperion 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server.

CVE-2014-0191
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2014 2 PoCs

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.