Latest CVE Feed
-
10.0
HIGHCVE-2002-0473
db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.... Read more
Affected Products : phpbb- EPSS Score: %14.54
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2019-5617
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-lev... Read more
Affected Products : computing_for_good\'s_basic_laboratory_information_system- EPSS Score: %1.91
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2002-0427
Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.... Read more
Affected Products : improved_mod_frontpage- EPSS Score: %0.47
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2019-5644
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, incl... Read more
Affected Products : computing_for_good\'s_basic_laboratory_information_system- EPSS Score: %1.91
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2002-0516
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.... Read more
Affected Products : squirrelmail- EPSS Score: %6.35
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0359
xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges.... Read more
Affected Products : irix- EPSS Score: %1.38
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0393
Buffer overflow in Red-M 1050 (Bluetooth Access Point) management web interface allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long administration password.... Read more
Affected Products : 1050ap_lan_acess_point- EPSS Score: %3.15
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0308
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.... Read more
Affected Products : admentor- EPSS Score: %0.43
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-5490
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may ... Read more
- EPSS Score: %1.10
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-1594
GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra user of the Codonics printer FTP service, (4) eNTEGRA for the eNTEGRA P&R user... Read more
Affected Products : entegra_p\&r- EPSS Score: %0.57
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2019-5402
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.... Read more
Affected Products : 3par_storeserv_management_console- EPSS Score: %3.18
- Published: Aug. 09, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-1481
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.... Read more
Affected Products : xitami- EPSS Score: %1.70
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-5347
A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.... Read more
Affected Products : intelligent_management_center- EPSS Score: %20.93
- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-1370
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and ... Read more
Affected Products : phplib- EPSS Score: %30.07
- Published: Jul. 21, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1264
Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.... Read more
- EPSS Score: %1.34
- Published: Jul. 19, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1240
The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.... Read more
Affected Products : secure_linux- EPSS Score: %0.46
- Published: Jul. 11, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3016
Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.... Read more
Affected Products : php-nuke- EPSS Score: %0.02
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1162
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.... Read more
- EPSS Score: %30.17
- Published: Jun. 23, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1113
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more
Affected Products : trollftpd- EPSS Score: %1.45
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2019-5128
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in... Read more
- EPSS Score: %90.29
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024