Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2006-5016

    Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory.... Read more

    Affected Products : e-vision_cms
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-5031

    Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a ... Read more

    Affected Products : cakephp cakephp
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 6.8

    MEDIUM
    CVE-2006-5043

    Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload... Read more

    Affected Products : joomla\! joomlaboard
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 6.8

    MEDIUM
    CVE-2006-5045

    Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php.... Read more

    Affected Products : com_pollxt
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-5052

    Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort."... Read more

    Affected Products : openssh
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-5051

    Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.... Read more

    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5030

    SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.... Read more

    Affected Products : content_management_system
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5032

    PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter.... Read more

    Affected Products : phpartenaire
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5049

    Unspecified vulnerability in Classifieds (com_classifieds) component 1.3 and earlier for Joomla! has unspecified impact and attack vectors.... Read more

    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5029

    SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report wa... Read more

    Affected Products : burning_board
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 6.8

    MEDIUM
    CVE-2006-5037

    MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. ... Read more

    Affected Products : mysource_matrix
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 4.3

    MEDIUM
    CVE-2006-5035

    Multiple cross-site scripting (XSS) vulnerabilities in Paul Smith Computer Services vCAP 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the statusmsg parameter in RegisterPage.cgi or (2) a URI corresponding to a nonexistent fi... Read more

    Affected Products : vcap
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5022

    PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.... Read more

    Affected Products : pnews
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5020

    Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.c... Read more

    Affected Products : solidstate
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5044

    Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.... Read more

    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5042

    Unspecified vulnerability in mosMedia (com_mosmedia) 1.0.8 and earlier for Joomla! has unspecified impact and attack vectors.... Read more

    Affected Products : com_mosmedia mosmedia
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 4.0

    MEDIUM
    CVE-2006-5018

    ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.... Read more

    Affected Products : contentkeeper
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-5050

    Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI.... Read more

    Affected Products : busybox
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5040

    Unspecified vulnerability in SEF404x (com_sef) for Joomla! has unspecified impact and attack vectors.... Read more

    Affected Products : com_sef sef4040x
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5017

    SQL injection vulnerability in admin/all_users.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to execute arbitrary SQL commands via the from parameter.... Read more

    Affected Products : e-vision_cms
    • Published: Sep. 27, 2006
    • Modified: Apr. 09, 2025
Showing 20 of 294863 Results