Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-5079

    PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.... Read more

    Affected Products : pabugs
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5085

    Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected into include/variables.php.... Read more

    Affected Products : pixel_motion_blog
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.8

    HIGH
    CVE-2006-5075

    The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client.... Read more

    Affected Products : solaris
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5084

    Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally re... Read more

    Affected Products : skype skype
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5076

    Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.... Read more

    Affected Products : back-end_cms
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5078

    PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.... Read more

    Affected Products : polaring
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5077

    PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : minerva
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 6.4

    MEDIUM
    CVE-2006-5086

    Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the origin... Read more

    Affected Products : pixel_motion_blog
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-4925

    packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.... Read more

    Affected Products : openssh
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.8

    HIGH
    CVE-2006-2937

    OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.... Read more

    Affected Products : openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.8

    HIGH
    CVE-2006-2940

    OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that req... Read more

    Affected Products : openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 4.3

    MEDIUM
    CVE-2006-4343

    The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.... Read more

    Affected Products : ubuntu_linux debian_linux openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-3738

    Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.... Read more

    Affected Products : openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5053

    PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content_page parameter.... Read more

    Affected Products : web-news
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5054

    SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter.... Read more

    Affected Products : iyzi_forum
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5055

    PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter.... Read more

    Affected Products : syntaxcms
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5062

    PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.... Read more

    Affected Products : pblang
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5061

    PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.... Read more

    Affected Products : advanced-clan-script
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5063

    Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote attackers to inject arbitrary web script or HTML by editing log entries in HTML mode.... Read more

    Affected Products : elog_web_logbook
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5070

    PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fsinit][objpath] parameter.... Read more

    Affected Products : facestones
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
Showing 20 of 294530 Results