16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2021-24186
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

CVE-2014-2446
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via vectors related to QAS.

CVE-2014-6519
Software Genérico Database
N/A
UNKNOWN
EPSS
3.1%
2014 1 PoC

Unspecified vulnerability in Oracle Java SE 7u67 and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect integrity via unknown vectors related to Hotspot.

CVE-2013-5818
Software Genérico Database
N/A
UNKNOWN
EPSS
1.8%
2013 2 PoCs

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5819 and CVE-2013-5831.

CVE-2021-24741
Support Board Web Database Windows
N/A
UNKNOWN
EPSS
58.3%
2021 CWE-89 5 PoCs

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

CVE-2015-4860
Software Genérico Database
N/A
UNKNOWN
EPSS
8.7%
2015 3 PoCs

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI, a different vulnerability than CVE-2015-4883.

CVE-2021-24392
WordPress Membership SwiftCloud.io Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2013-3793
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2013 3 PoCs

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.

CVE-2021-24143
AccessPress Social Icons Database
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

CVE-2023-3435
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

CVE-2007-5998
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2007 1 PoC

SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.

CVE-2007-2543
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2007 1 PoC

SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

CVE-2007-3430
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.

CVE-2007-3453
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid parameter to certain components.

CVE-2007-1255
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2007 1 PoC

Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/. NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks.

CVE-2014-4299
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, CVE-2014-4300, CVE-2014-6452, CVE-2014-6454, and CVE-2014-6542.

CVE-2013-3822
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2013 1 PoC

Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1 allows remote attackers to affect integrity via unknown vectors related to Web Client (CS).

CVE-2021-44097
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.

CVE-2021-43701
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.

CVE-2021-31816
Octopus Server Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.