Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2005-2157

    PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.... Read more

    Affected Products : nabopoll
    • EPSS Score: %1.45
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2162

    PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.... Read more

    Affected Products : myguestbook
    • EPSS Score: %1.74
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2165

    read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.... Read more

    Affected Products : globalnotescript
    • EPSS Score: %2.16
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2168

    delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.... Read more

    Affected Products : plague_news_system
    • EPSS Score: %0.42
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2019

    ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to... Read more

    Affected Products : freebsd
    • EPSS Score: %0.22
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2139

    PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.... Read more

    Affected Products : pavsta_auto_site
    • EPSS Score: %0.46
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2113

    SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger... Read more

    Affected Products : xoops
    • EPSS Score: %0.97
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2112

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.... Read more

    Affected Products : xoops
    • EPSS Score: %0.56
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2111

    login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.... Read more

    Affected Products : community_link_pro_web_editor
    • EPSS Score: %2.88
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2093

    Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length h... Read more

    Affected Products : application_server
    • EPSS Score: %2.59
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2110

    WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an erro... Read more

    Affected Products : wordpress
    • EPSS Score: %1.23
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1931

    GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.... Read more

    Affected Products : goodtech_smtp_server
    • EPSS Score: %4.01
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2085

    Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.... Read more

    Affected Products : inframail_advantage
    • EPSS Score: %6.42
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1922

    The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.... Read more

    Affected Products : clamav
    • EPSS Score: %0.74
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2105

    Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.... Read more

    Affected Products : ios
    • EPSS Score: %0.78
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2086

    PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.... Read more

    Affected Products : phpbb
    • EPSS Score: %84.84
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2108

    SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.... Read more

    Affected Products : wordpress
    • EPSS Score: %1.06
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-2145

    The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.... Read more

    Affected Products : prevx_pro_2005
    • EPSS Score: %0.06
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0360

    The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.... Read more

    Affected Products : log_sink_class_activex_control
    • EPSS Score: %6.37
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2005-1923

    The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to ... Read more

    Affected Products : clamav
    • EPSS Score: %0.66
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291625 Results