1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-29282
Software Genérico Database
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.

CVE-2020-20950
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

CVE-2020-35378
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.

CVE-2020-18215
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.

CVE-2020-15180
mariadb Database
N/A
UNKNOWN
EPSS
4.6%
2020 CWE-20 1 PoC

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

CVE-2020-24791
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2020-12429
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.

CVE-2020-12850
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio is responsible for running all the services and binaries that are contained in the Pydio Cells web application package, such as mysqld, cells, among others. This user has privileges restricted to run those services and nothing more.

CVE-2020-29280
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.

CVE-2020-35122
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.

CVE-2020-10547
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-8158
typeorm Database
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-471 1 PoC

Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

CVE-2020-13631
Software Genérico Database
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVE-2020-15849
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for authorization bypass and taking over additional accounts by means of modifying password-reset tokens stored in the database. Remote command execution is also possible by leveraging this to abuse the Yii framework's bizRule functionality, allowing for arbitrary PHP code to be executed by the applicati

CVE-2020-35270
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.

CVE-2020-26668
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function.

CVE-2020-23980
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.

CVE-2020-20949
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

CVE-2020-14960
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,

CVE-2020-11655
Software Genérico Database
N/A
UNKNOWN
EPSS
4.9%
2020 4 PoCs

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.