Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.8

    MEDIUM
    CVE-2006-2246

    Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry.... Read more

    Affected Products : ublog
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-2247

    WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.... Read more

    Affected Products : webcalendar
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-2260

    Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more

    Affected Products : drupal
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-2261

    PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.... Read more

    Affected Products : acal
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-2262

    Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more

    Affected Products : singapore
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-2269

    Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.... Read more

    Affected Products : mybloggie
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 6.5

    MEDIUM
    CVE-2006-2264

    Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit... Read more

    Affected Products : calendar_manager_pro
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.8

    MEDIUM
    CVE-2006-2243

    Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection... Read more

    Affected Products : news_portal
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-2250

    CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message.... Read more

    Affected Products : cutenews
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-2249

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.... Read more

    Affected Products : cutenews
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-2242

    acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command.... Read more

    Affected Products : acftp
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-2270

    PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter.... Read more

    Affected Products : jetbox_cms
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-2244

    Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php.... Read more

    Affected Products : news_portal
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-2248

    Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension.... Read more

    Affected Products : xeneo_web_server
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-2239

    SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows remote attackers to execute arbitrary SQL commands via the nid parameter.... Read more

    Affected Products : newsadmin
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-2251

    SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter.... Read more

    Affected Products : invision_community_blog
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-2161

    Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name.... Read more

    Affected Products : cam_unzip abakt tzipbuilder
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0515

    Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET metho... Read more

    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-2255

    Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discuss... Read more

    Affected Products : community_portal
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-2256

    PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the eqdkp_root_path parameter.... Read more

    Affected Products : eqdkp
    • Published: May. 09, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294733 Results