1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-5515
Software Genérico Web Database
N/A
UNKNOWN
EPSS
62.4%
2020 2 PoCs

Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.

CVE-2020-10549
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-15539
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.

CVE-2020-25695
postgresql Database
N/A
UNKNOWN
EPSS
23.8%
2020 CWE-89 1 PoC

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-8596
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).

CVE-2020-17446
Software Genérico Database
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.

CVE-2020-15363
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
14.2%
2020 1 PoC

The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

CVE-2020-25952
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-13249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVE-2020-22198
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

CVE-2020-25409
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.

CVE-2020-15526
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications. These TLS security checks are also ignored during monitoring of VMware machines. This would make SQL Monitor vulnerable to potential man-in-the-middle attacks when sending alert notification emails, posting to Slack or posting to webhooks. The vulnerability is fixed in version 10.1.7.

CVE-2020-10239
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

CVE-2020-5766
SRS Simple Hits Counter Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
39.1%
2020 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

CVE-2020-13993
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket.

CVE-2020-26773
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.

CVE-2020-22210
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
43.9%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2020-25362
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2020 3 PoCs

The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.

CVE-2020-15924
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.

CVE-2020-23976
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.