Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-3364

    SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more

    Affected Products : blog_cms
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3380

    Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more

    Affected Products : freestyle_wiki
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3390

    WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.... Read more

    Affected Products : wordpress
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3387

    Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code t... Read more

    Affected Products : fusion_news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3376

    Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a W... Read more

    Affected Products : libwmf wv2
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3372

    Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.... Read more

    Affected Products : safari
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3374

    PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter.... Read more

    Affected Products : randshop
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3381

    SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.... Read more

    Affected Products : sturgeon_upload
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-3373

    Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary files, related to logfetch running as setuid root.... Read more

    Affected Products : hobbit_monitor
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3375

    PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter.... Read more

    Affected Products : randshop
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2006-3393

    Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded du... Read more

    Affected Products : nascar_racing
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3363

    PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.... Read more

    Affected Products : xoops_glossaire_module
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3384

    SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.... Read more

    Affected Products : news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3386

    index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.... Read more

    Affected Products : news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3369

    Kamikaze-QSCM 0.1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more

    Affected Products : kamikaze-qscm
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-3382

    Cross-site scripting (XSS) vulnerability in search.php in mAds 1.0 allows remote attackers to inject arbitrary web script or HTML via the "search string".... Read more

    Affected Products : mads
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-3399

    Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message, a variant of CVE-2004-1632.... Read more

    Affected Products : moniwiki
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.8

    MEDIUM
    CVE-2006-3388

    Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.... Read more

    Affected Products : phpmyadmin
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3389

    index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party ... Read more

    Affected Products : wordpress
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3362

    Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when inst... Read more

    Affected Products : toendacms geeklog
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294837 Results