1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-35674
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted payload that can result in sensitive information being extracted from the database, eventually leading into an application takeover. This vulnerability was introduced as a result of the developer trying to roll their own sanitization implementation in order to allow the application to be used in legacy environments.

CVE-2020-13871
Software Genérico Database
N/A
UNKNOWN
EPSS
2.4%
2020 4 PoCs

SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.

CVE-2020-14147
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.

CVE-2020-36115
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.

CVE-2020-25760
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 5 PoCs

Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

CVE-2020-13946
Apache Cassandra Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

CVE-2020-15504
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

CVE-2020-24932
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

CVE-2020-10230
Software Genérico Web Database
N/A
UNKNOWN
EPSS
28.9%
2020 1 PoC

CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

CVE-2020-9483
Apache SkyWalking Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 2 PoCs

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.

CVE-2020-28657
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.

CVE-2020-13380
Software Genérico Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

openSIS before 7.4 allows SQL Injection.

CVE-2020-35327
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php

CVE-2020-10218
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.

CVE-2020-28074
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.

CVE-2020-29287
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.5%
2020 2 PoCs

An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.

CVE-2020-11656
Software Genérico Database
N/A
UNKNOWN
EPSS
6.1%
2020 4 PoCs

In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.

CVE-2020-20300
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
56.1%
2020 0 PoCs

SQL injection vulnerability in the wp_where function in WeiPHP 5.0.

CVE-2020-13692
Software Genérico Database
N/A
UNKNOWN
EPSS
7.8%
2020 1 PoC

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.