16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2007-2561
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-6115.

CVE-2007-4362
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2007 1 PoC

SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVE-2007-2662
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to the top-level URI.

CVE-2007-1615
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2007 1 PoC

SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVE-2014-6456
Software Genérico Database
N/A
UNKNOWN
EPSS
7.6%
2014 2 PoCs

Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2013-2447
Software Genérico Database
N/A
UNKNOWN
EPSS
3.9%
2013 3 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to obtain a socket's local address via vectors involving inconsistencies between Socket.getLocalAddress and InetAddress.getLocalHost.

CVE-2021-24285
Car Seller - Auto Classifieds Script Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2021 CWE-89 1 PoC

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

CVE-2021-27316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

CVE-2013-0427
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2013 1 PoC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Libraries. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to interrupt certain threads that should not be interrupted.

CVE-2021-44095
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.

CVE-2021-26201
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.

CVE-2021-24898
Editable Table Simple Fast FrontEnd From Sql tables Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2014-6587
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2014 2 PoCs

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

CVE-2013-0399
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 2 PoCs

Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Umount.

CVE-2021-24402
WP iCommerce – the first interactive ecommerce for wordpress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

CVE-2021-36351
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.

CVE-2021-37807
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

CVE-2007-1618
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVE-2014-0425
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Unspecified vulnerability in the PeopleSoft Enterprise SCM Services Procurement component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

CVE-2013-2415
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2013 3 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows local users to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "processing of MTOM attachments" and the creation of temporary files with weak permissions.