1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-35263
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

CVE-2020-18714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.

CVE-2020-10802
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.

CVE-2020-13630
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

CVE-2020-15873
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.0%
2020 2 PoCs

In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.

CVE-2020-24197
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter.

CVE-2020-14062
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.6%
2020 7 PoCs

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

CVE-2020-29550
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The following files contain the password in cleartext: Profiles/urve/files/sql_db.backup, Server/data/pg_wal/000000010000000A000000DD, Server/data/base/16384/18617, and Server/data/base/17202/8708746. This causes the password to be displayed as cleartext in the HTML code as roomsreservationimport_password in /urve/roomsreservationimport/roomsreservationimport/upd

CVE-2020-28183
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

CVE-2020-14982
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database.

CVE-2020-28702
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.

CVE-2020-35765
Software Genérico Database
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

CVE-2020-35012
Events Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-89 1 PoC

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

CVE-2020-29214
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
45.3%
2020 1 PoC

SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.

CVE-2020-9314
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
12.0%
2020 1 PoC

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

CVE-2020-15052
Software Genérico Database
N/A
UNKNOWN
EPSS
9.1%
2020 1 PoC

An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.

CVE-2020-9318
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert settings in the UI. This is fixed in 9.2.15.

CVE-2020-15714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2020-18020
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.4%
2020 1 PoC

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.