13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-25508
Hazir Ilan Sitesi Scripti Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'kat' parameter. Attackers can send GET requests to the katgetir.php endpoint with malicious 'kat' values to extract sensitive database information.

CVE-2019-25439
NoviSmart CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.

CVE-2019-25640
Inout Article Base CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.

CVE-2019-25537
Netartmedia Event Portal Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL payloads in the Email field to extract sensitive database information.

CVE-2019-17330
TIBCO EBX Web
8.8
HIGH
EPSS
0.3%
2019 1 PoC

The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions up to and including 5.8.1.fixR, versions 5.9.3, 5.9.4, 5.9.5, and 5.9.6.

CVE-2019-25499
Simple Job Script Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.

CVE-2019-25366
microASP (Portal+) CMS Web Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to extract sensitive database information like the current database name.

CVE-2019-25501
Simple Job Script Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attackers can send POST requests to delete_application_ajax.php with crafted payloads to extract sensitive data, bypass authentication, or modify database contents.

CVE-2019-25491
Homey BNB (Airbnb Clone Script) Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to extract sensitive database information.

CVE-2019-25697
CMSsite Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php with malicious cat_id values to extract sensitive database information including usernames and credentials.

CVE-2019-25575
SimplePress CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.

CVE-2019-25538
202CMS Web Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send crafted requests with malicious SQL statements in the log_user field to extract sensitive database information or modify database contents.

CVE-2019-25142
Materialis Web Windows
8.8
HIGH
EPSS
0.6%
2019 CWE-862 1 PoC

The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it possible for authenticated attackers to change otherwise restricted options.

CVE-2019-25506
FreeSMS Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to /pages/crc_handler.php?method=login to authenticate as any known user and subsequently modify their password via the profile update function.

CVE-2019-25260
OXID eShop Web Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

CVE-2019-25235
Smartwares HOME easy Web
8.8
HIGH
EPSS
0.4%
2019 CWE-639 2 PoCs

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.

CVE-2019-25507
Ashop Shopping Cart Software Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive database information.

CVE-2019-5031
Foxit Web
8.8
HIGH
EPSS
1.0%
2019 CWE-703 1 PoC

An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVE-2019-25320
elearning-script Web
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the system.

CVE-2019-25325
Smart Home Web Database
8.8
HIGH
EPSS
0.5%
2019 CWE-89 2 PoCs

Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. Attackers can inject malicious SQL code like ' or 1=1# to manipulate login queries and gain unauthorized access to the application.