Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2005-2148

    Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack s... Read more

    Affected Products : cacti
    • EPSS Score: %4.13
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-2147

    Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.... Read more

    Affected Products : trac
    • EPSS Score: %0.42
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-2149

    config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.... Read more

    Affected Products : cacti
    • EPSS Score: %1.29
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2152

    SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.... Read more

    Affected Products : geeklog
    • EPSS Score: %0.50
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.5

    MEDIUM
    CVE-2005-1916

    linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.... Read more

    Affected Products : debian_linux ekg
    • EPSS Score: %0.04
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2168

    delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.... Read more

    Affected Products : plague_news_system
    • EPSS Score: %0.42
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2166

    SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.... Read more

    Affected Products : plague_news_system
    • EPSS Score: %0.31
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2167

    Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.... Read more

    Affected Products : plague_news_system
    • EPSS Score: %0.28
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2162

    PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.... Read more

    Affected Products : myguestbook
    • EPSS Score: %1.74
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2165

    read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.... Read more

    Affected Products : globalnotescript
    • EPSS Score: %2.16
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2084

    Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more

    Affected Products : community_server_forums
    • EPSS Score: %0.30
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-1932

    Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arb... Read more

    Affected Products : lpanel
    • EPSS Score: %0.21
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-2146

    SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.... Read more

    Affected Products : tectia_server
    • EPSS Score: %0.04
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2068

    FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.... Read more

    Affected Products : freebsd
    • EPSS Score: %0.34
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2087

    Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CL... Read more

    Affected Products : internet_explorer ie
    • EPSS Score: %65.27
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2019

    ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to... Read more

    Affected Products : freebsd
    • EPSS Score: %0.22
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2139

    PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.... Read more

    Affected Products : pavsta_auto_site
    • EPSS Score: %0.46
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2109

    wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.... Read more

    Affected Products : wordpress
    • EPSS Score: %1.08
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2088

    The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Enc... Read more

    Affected Products : debian_linux http_server
    • EPSS Score: %82.74
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-0393

    The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.... Read more

    Affected Products : crip
    • EPSS Score: %0.05
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291551 Results