Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2002-0395

    The TFTP server for Red-M 1050 (Bluetooth Access Point) can not be disabled and makes it easier for remote attackers to crack the administration password via brute force methods.... Read more

    Affected Products : 1050ap_lan_acess_point
    • EPSS Score: %1.21
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-1138

    SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.... Read more

    • EPSS Score: %0.72
    • Published: Sep. 17, 1993
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0613

    dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.... Read more

    Affected Products : dnstools
    • EPSS Score: %3.64
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0988

    Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.... Read more

    Affected Products : unixware openunix
    • EPSS Score: %1.00
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-0636

    Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.... Read more

    Affected Products : foxmail_email_server
    • EPSS Score: %5.91
    • Published: Mar. 02, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1428

    index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.... Read more

    Affected Products : dotproject
    • EPSS Score: %2.68
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1466

    CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.... Read more

    Affected Products : b2
    • EPSS Score: %1.18
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1537

    admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".... Read more

    Affected Products : phpbb
    • EPSS Score: %0.41
    • Published: Mar. 31, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1560

    index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.... Read more

    Affected Products : gbook
    • EPSS Score: %2.36
    • Published: Mar. 31, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-2250

    Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored procedure or (2) a long database name argument to the DBCC CHECKVERIFY function.... Read more

    Affected Products : adaptive_server
    • EPSS Score: %16.47
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0280

    Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.... Read more

    Affected Products : cmailserver
    • EPSS Score: %11.16
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0640

    BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %0.65
    • Published: Aug. 27, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0134

    Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.... Read more

    • EPSS Score: %2.03
    • Published: Mar. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2007-5383

    The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_... Read more

    Affected Products : speedtouch_7g_router home_hub
    • EPSS Score: %1.11
    • Published: Oct. 12, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-5657

    TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.... Read more

    • EPSS Score: %11.47
    • Published: Jan. 16, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-5658

    Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-len... Read more

    • EPSS Score: %15.94
    • Published: Jan. 16, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4592

    Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.... Read more

    Affected Products : sports_clubs_web_portal
    • EPSS Score: %2.77
    • Published: Oct. 16, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-5890

    Directory traversal vulnerability in index.php in easyGB 2.1.1 allows remote attackers to include arbitrary files via the DatabaseType parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inform... Read more

    Affected Products : easygb
    • EPSS Score: %2.80
    • Published: Nov. 08, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-6011

    Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details... Read more

    Affected Products : bughotel_reservation_system
    • EPSS Score: %0.60
    • Published: Nov. 16, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-6044

    Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it i... Read more

    Affected Products : websphere_mq
    • EPSS Score: %0.54
    • Published: Nov. 20, 2007
    • Modified: Apr. 09, 2025
Showing 20 of 291058 Results