Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-1767

    Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (... Read more

    Affected Products : indexu
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1774

    HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.... Read more

    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1775

    Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_g... Read more

    Affected Products : phpbb
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-1782

    Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ... Read more

    Affected Products : solaris sunos
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1777

    Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP seq... Read more

    Affected Products : simplog
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1756

    MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area.... Read more

    Affected Products : md_news
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1761

    Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS a... Read more

    Affected Products : blur6ex
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2006-1764

    Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this informat... Read more

    Affected Products : hosting_controller
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1757

    Cross-site scripting (XSS) vulnerability in index.php in Vegadns 0.99 allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more

    Affected Products : vegadns
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1762

    Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter. NOTE: this issue can be exploited to produce resultant XSS when the parameter has XSS manipulations, and path di... Read more

    Affected Products : blur6ex
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1763

    Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_permaPost action to the blog shard (engine/shards/blog.php), or a (3) g_viewCon... Read more

    Affected Products : blur6ex
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1760

    Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orang... Read more

    Affected Products : jetphoto
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1758

    SQL injection vulnerability in index.php in Vegadns 0.99 allows remote attackers to execute arbitrary SQL commands via the cid parameter.... Read more

    Affected Products : vegadns
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1755

    SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more

    Affected Products : md_news
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1759

    Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter.... Read more

    Affected Products : confixx
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1754

    SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.... Read more

    Affected Products : confixx
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-1523

    The __group_complete_signal function in the RCU signal handling (signal.c) in Linux kernel 2.6.16, and possibly other versions, has unknown impact and attack vectors related to improper use of BUG_ON.... Read more

    Affected Products : linux_kernel
    • Published: Apr. 12, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1745

    Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third... Read more

    Affected Products : bitweaver
    • Published: Apr. 12, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1747

    PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.... Read more

    Affected Products : virtual_war
    • Published: Apr. 12, 2006
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2006-1744

    Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.... Read more

    Affected Products : bsdgames
    • Published: Apr. 12, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294690 Results