1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-28091
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.5%
2020 1 PoC

cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.

CVE-2020-13433
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

CVE-2020-35329
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.

CVE-2020-24862
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.

CVE-2020-15476
Software Genérico Database
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

CVE-2020-35847
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVE-2020-25004
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-8804
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.

CVE-2020-24841
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2020-9386
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

CVE-2020-16267
Software Genérico Database
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.

CVE-2020-18713
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php

CVE-2020-25990
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2020-1963
Apache Ignite Web Database
N/A
UNKNOWN
EPSS
4.7%
2020 1 PoC

Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.

CVE-2020-15394
Software Genérico Web Database
N/A
UNKNOWN
EPSS
31.4%
2020 1 PoC

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

CVE-2020-35151
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

CVE-2020-35263
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

CVE-2020-18714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.

CVE-2020-10802
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.