1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-35545
Software Genérico Database
N/A
UNKNOWN
EPSS
8.4%
2020 1 PoC

Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

CVE-2020-24913
Software Genérico Web Database
N/A
UNKNOWN
EPSS
43.1%
2020 3 PoCs

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

CVE-2020-10546
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-35276
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

CVE-2020-10220
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 4 PoCs

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

CVE-2020-7009
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-266 1 PoC

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

CVE-2020-9547
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.3%
2020 7 PoCs

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

CVE-2020-5723
Grandstream UCM6200 series Database
N/A
UNKNOWN
EPSS
51.8%
2020 CWE-312 1 PoC

The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

CVE-2020-27481
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.0%
2020 0 PoCs

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

CVE-2020-28960
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.

CVE-2020-6577
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

CVE-2020-36002
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.

CVE-2020-14349
PostgreSQL Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

CVE-2020-8165
https://github.com/rails/rails Web Database
N/A
UNKNOWN
EPSS
90.1%
2020 CWE-502 8 PoCs

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

CVE-2020-12104
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.

CVE-2020-23045
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules.

CVE-2020-18717
Software Genérico Web Database
N/A
UNKNOWN
EPSS
7.2%
2020 1 PoC

SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.

CVE-2020-25269
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server.

CVE-2020-36003
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.

CVE-2020-28073
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.