Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.8

    MEDIUM
    CVE-2006-1331

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter.... Read more

    Affected Products : noahs_classifieds
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-1325

    Cross-site scripting (XSS) vulnerability in Streber 0.055 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more

    Affected Products : streber
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1326

    Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index... Read more

    Affected Products : invision_power_board
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1328

    SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldname, or (3) url parameter.... Read more

    Affected Products : download_counter_wallpaper
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1061

    Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.... Read more

    Affected Products : curl curl
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-1324

    Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.... Read more

    Affected Products : burning_board
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-1333

    Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.... Read more

    Affected Products : betaparticle_blog
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1330

    Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.... Read more

    Affected Products : phpwebsite
    • Published: Mar. 21, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-1323

    Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZIP, or (4) TAR.GZ archive with a file whose file name contains ".." sequences.... Read more

    Affected Products : winhki
    • Published: Mar. 20, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1322

    Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.... Read more

    Affected Products : netware netware_ftp_server
    • Published: Mar. 20, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1320

    util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.... Read more

    Affected Products : rssh
    • Published: Mar. 20, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1321

    Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.... Read more

    Affected Products : webcheck
    • Published: Mar. 20, 2006
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2006-1319

    chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes chpst to assign permissions for the root group due to in... Read more

    Affected Products : runit
    • Published: Mar. 20, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-1286

    Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database.... Read more

    Affected Products : ghost_solutions_suite norton_ghost
    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1289

    Multiple SQL injection vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, (3) team, (4) level, (5) status, (6) teamname, and (7) teamlead parameters in (a)... Read more

    Affected Products : milkeyway_captive_portal
    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1297

    Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application... Read more

    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2006-1298

    Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Ba... Read more

    Affected Products : backup_exec
    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1295

    Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.... Read more

    Affected Products : spip
    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1294

    PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter.... Read more

    Affected Products : knowledgebasepublisher
    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1291

    publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with ... Read more

    Affected Products : php_icalendar
    • Published: Mar. 19, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 293577 Results