16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2013-0386
Software Genérico Database
N/A
UNKNOWN
EPSS
1.4%
2013 3 PoCs

Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.

CVE-2023-40852
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.

CVE-2021-44245
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

CVE-2014-0414
Software Genérico DevOps Web Database
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality via vectors related to HTTP Request Handling.

CVE-2013-3779
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2013 1 PoC

Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization All 4.6 releases including 4.63 and 4.7 prior to 4.71 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web UI.

CVE-2021-22144
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVE-2021-24626
Chameleon CSS Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-89 2 PoCs

The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL Injection

CVE-2013-2422
Software Genérico Database
N/A
UNKNOWN
EPSS
15.5%
2013 2 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.

CVE-2021-44249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.

CVE-2023-3983
Advantech iView Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

CVE-2021-42077
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

CVE-2007-2854
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.

CVE-2014-0385
Software Genérico Database
N/A
UNKNOWN
EPSS
1.6%
2014 1 PoC

Unspecified vulnerability in Oracle Java SE 7u45, when installing on OS X, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.

CVE-2013-1522
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2013 2 PoCs

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Content Server.

CVE-2023-27847
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
73.1%
2023 1 PoC

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

CVE-2013-1528
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2013 2 PoCs

Unspecified vulnerability in the Oracle HRMS component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Payroll.

CVE-2021-26935
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.

CVE-2013-5762
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Unspecified vulnerability in the Oracle Siebel CTMS component in Oracle Industry Applications 8.1.1.x allows local users to affect confidentiality and availability via unknown vectors related to SC-OC Integration.

CVE-2013-1510
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2013 2 PoCs

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2015-0419.