Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-5641

    SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more

    Affected Products : announcement_script
    • Published: Nov. 01, 2006
    • Modified: Apr. 09, 2025
  • 6.8

    MEDIUM
    CVE-2006-5634

    Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc param... Read more

    Affected Products : phpprofiles
    • Published: Nov. 01, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5638

    Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.... Read more

    Affected Products : phpmyring
    • Published: Nov. 01, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5637

    PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.... Read more

    Affected Products : faq_administrator
    • Published: Nov. 01, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-5633

    Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the... Read more

    Affected Products : firefox seamonkey
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5630

    Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID parameter in a disableforum action in DisableForum.asp and (2) create an arbitrary forum virtual directory via... Read more

    Affected Products : hosting_controller
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 6.8

    MEDIUM
    CVE-2006-5631

    Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via arbitrary query strings when the action parameter is not "1", as demonstrated using script in the action paramete... Read more

    Affected Products : ig_shop
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 6.8

    MEDIUM
    CVE-2006-5632

    Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unkn... Read more

    Affected Products : ig_shop
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5629

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vu... Read more

    Affected Products : hosting_controller
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5625

    PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.... Read more

    Affected Products : n_x_wcms
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5623

    PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.... Read more

    Affected Products : ee_tool
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5627

    Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/in... Read more

    Affected Products : qnecms
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5628

    SQL injection vulnerability in login.asp in UNISOR Content Management System (CMS) allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass fields.... Read more

    Affected Products : unisor_cms
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5622

    SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.... Read more

    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 4.3

    MEDIUM
    CVE-2006-5626

    Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the ... Read more

    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5621

    PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.... Read more

    Affected Products : ask_rave
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5620

    PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a differen... Read more

    Affected Products : minibill
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5624

    Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of... Read more

    Affected Products : mpcs
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5606

    Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.... Read more

    Affected Products : bytesfall_explorer
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 2.1

    LOW
    CVE-2006-5619

    The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabel... Read more

    Affected Products : linux_kernel
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
Showing 20 of 294860 Results