1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-20949
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

CVE-2020-14960
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,

CVE-2020-11655
Software Genérico Database
N/A
UNKNOWN
EPSS
4.9%
2020 4 PoCs

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

CVE-2020-25034
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.

CVE-2020-22807
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.

CVE-2020-11942
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

CVE-2020-25889
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2020 4 PoCs

Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.

CVE-2020-10983
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.

CVE-2020-7010
Elastic Cloud on Kubernetes DevOps Database Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-335 1 PoC

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

CVE-2020-15308
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.

CVE-2020-18662
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVE-2020-27557
Software Genérico Database
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.

CVE-2020-13118
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

CVE-2020-26051
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.

CVE-2020-25475
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.

CVE-2020-35427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-5841
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.

CVE-2020-11579
Software Genérico Web Database
N/A
UNKNOWN
EPSS
51.4%
2020 3 PoCs

An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.

CVE-2020-25254
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnection_LocalOrLinkedServer, CreateFilterFriendlyView, or AddWorkViewLinkedServer.

CVE-2020-11530
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 2 PoCs

A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.