Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2006-5626

    Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the ... Read more

    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5624

    Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of... Read more

    Affected Products : mpcs
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5622

    SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.... Read more

    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5628

    SQL injection vulnerability in login.asp in UNISOR Content Management System (CMS) allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass fields.... Read more

    Affected Products : unisor_cms
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5625

    PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.... Read more

    Affected Products : n_x_wcms
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5623

    PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.... Read more

    Affected Products : ee_tool
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5606

    Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.... Read more

    Affected Products : bytesfall_explorer
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 2.1

    LOW
    CVE-2006-5619

    The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabel... Read more

    Affected Products : linux_kernel
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.2

    HIGH
    CVE-2006-4248

    thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.... Read more

    Affected Products : thttpd
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 2.6

    LOW
    CVE-2006-5614

    Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dere... Read more

    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5612

    PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the aide parameter.... Read more

    Affected Products : gestart
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5615

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.... Read more

    Affected Products : textpattern
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-5618

    Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the ad_direct parameter.... Read more

    Affected Products : netref
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5613

    PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter... Read more

    Affected Products : mp3_streaming_downsampler
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5617

    Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter.... Read more

    Affected Products : thepeak_file_upload_manager
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-5616

    Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : suse_linux openpbs
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2006-5610

    PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : fully_modded_phpbb
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-5611

    Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related... Read more

    Affected Products : bluetooth_stack
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-5609

    Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.... Read more

    Affected Products : torrentflux
    • Published: Oct. 30, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5608

    SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "parameters from URLs."... Read more

    Affected Products : extended_tracker
    • Published: Oct. 30, 2006
    • Modified: Apr. 09, 2025
Showing 20 of 294848 Results