Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.8

    MEDIUM
    CVE-2006-1121

    Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.... Read more

    Affected Products : cutenews
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-1123

    SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.... Read more

    Affected Products : d2kblog
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-1122

    Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more

    Affected Products : d2kblog
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1120

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in ... Read more

    Affected Products : dcp-portal
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1124

    Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command.... Read more

    Affected Products : revilloc_mailserver
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-0743

    Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.... Read more

    Affected Products : log4net
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 4.0

    MEDIUM
    CVE-2006-1119

    fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.... Read more

    Affected Products : cpanel fantastico_de_luxe
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1113

    SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more

    Affected Products : loudblog
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1108

    SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more

    Affected Products : nmdeluxe
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1100

    Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of input data.... Read more

    Affected Products : cube sauerbraten
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1097

    Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.... Read more

    Affected Products : datenbank_module
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1104

    Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php; and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header field... Read more

    Affected Products : pixelpost
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1094

    SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.... Read more

    Affected Products : burning_board datenbank_module
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1103

    engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault) via a client that does not completely join the game and times out, which results in a null pointer dere... Read more

    Affected Products : cube sauerbraten
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1089

    Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.... Read more

    Affected Products : punbb
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1105

    Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the vendor has disputed some issues from the original disclosure, but due t... Read more

    Affected Products : pixelpost
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1098

    Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher... Read more

    Affected Products : nz_ecommerce
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-1092

    Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to al... Read more

    Affected Products : solaris sunos
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1099

    PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party informat... Read more

    Affected Products : logit
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1118

    SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.... Read more

    Affected Products : bmail
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294858 Results