1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-28073
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.

CVE-2020-11998
Apache ActiveMQ Web Database
N/A
UNKNOWN
EPSS
6.9%
2020 6 PoCs

A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade

CVE-2020-27207
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of service attack can be performed. For example, a SQL injection can be used to execute the crafted SQL command sequence. After that, some unexpected RAM data is read.

CVE-2020-18116
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.

CVE-2020-14060
Software Genérico Web Database
N/A
UNKNOWN
EPSS
8.7%
2020 7 PoCs

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

CVE-2020-10982
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.

CVE-2020-25487
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.

CVE-2020-6455
Chrome Database
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-35846
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 4 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

CVE-2020-27733
Software Genérico Database
N/A
UNKNOWN
EPSS
4.4%
2020 1 PoC

Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

CVE-2020-3984
VMware SD-WAN Orchestrator Web Database
N/A
UNKNOWN
EPSS
16.6%
2020 1 PoC

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.

CVE-2020-15713
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2020-7105
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

CVE-2020-8656
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
81.8%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

CVE-2020-29241
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.

CVE-2020-6637
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2020 1 PoC

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

CVE-2020-28091
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.5%
2020 1 PoC

cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.

CVE-2020-13433
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

CVE-2020-35329
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.

CVE-2020-24862
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.