16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2007-1899
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2007 1 PoC

Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.

CVE-2014-10020
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.0%
2014 2 PoCs

SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVE-2013-5311
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2013 1 PoC

Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. NOTE: the cat parameter is already covered by CVE-2008-4157.

CVE-2021-37749
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2013-7334
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Cross-site request forgery (CSRF) vulnerability in ImageCMS before 4.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the q parameter, related to CVE-2012-6290.

CVE-2021-43650
Software Genérico Database
N/A
UNKNOWN
EPSS
1.0%
2021 2 PoCs

WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.

CVE-2014-2440
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2014 2 PoCs

Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2013-1516
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2013 2 PoCs

Unspecified vulnerability in the Oracle WebCenter Capture component in Oracle Fusion Middleware 10.1.3.5.1 allows remote authenticated users to affect availability via unknown vectors related to Import Server.

CVE-2021-24827
Asgaros Forum Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

CVE-2021-41920
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

CVE-2021-24131
Anti-Spam by CleanTalk Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 1 PoC

Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).

CVE-2013-3813
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality and integrity via vectors related to Libraries/PAM-Unix.

CVE-2023-5640
Article analytics Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

CVE-2021-22132
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-522 1 PoC

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVE-2007-1292
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.9%
2007 2 PoCs

SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to achieve."

CVE-2007-3812
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2007 1 PoC

SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php.

CVE-2014-2470
Software Genérico Database
N/A
UNKNOWN
EPSS
1.3%
2014 1 PoC

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Security.

CVE-2013-3769
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2013 1 PoC

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote attackers to affect integrity via unknown vectors related to Site Studio.