Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2005-2158

    A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.... Read more

    Affected Products : jbpm
    • EPSS Score: %0.64
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2153

    SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.... Read more

    Affected Products : osticket_sts
    • EPSS Score: %0.58
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2157

    PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.... Read more

    Affected Products : nabopoll
    • EPSS Score: %1.45
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2166

    SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.... Read more

    Affected Products : plague_news_system
    • EPSS Score: %0.31
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2164

    SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more

    Affected Products : covide
    • EPSS Score: %0.43
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 5.5

    MEDIUM
    CVE-2005-1916

    linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.... Read more

    Affected Products : debian_linux ekg
    • EPSS Score: %0.04
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2155

    PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.... Read more

    Affected Products : easyphpcalendar
    • EPSS Score: %2.11
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-2149

    config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.... Read more

    Affected Products : cacti
    • EPSS Score: %1.29
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-2147

    Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.... Read more

    Affected Products : trac
    • EPSS Score: %0.42
    • Published: Jul. 06, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2108

    SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.... Read more

    Affected Products : wordpress
    • EPSS Score: %1.06
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2085

    Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.... Read more

    Affected Products : inframail_advantage
    • EPSS Score: %6.42
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1922

    The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.... Read more

    Affected Products : clamav
    • EPSS Score: %0.74
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2086

    PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.... Read more

    Affected Products : phpbb
    • EPSS Score: %86.51
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2105

    Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.... Read more

    Affected Products : ios
    • EPSS Score: %0.78
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2005-1923

    The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to ... Read more

    Affected Products : clamav
    • EPSS Score: %0.66
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2081

    Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.... Read more

    Affected Products : asterisk
    • EPSS Score: %0.35
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2094

    Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which cause... Read more

    Affected Products : one_web_server
    • EPSS Score: %1.56
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-1917

    kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.... Read more

    Affected Products : kpopper
    • EPSS Score: %0.08
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-2136

    Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrar... Read more

    • EPSS Score: %0.15
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2138

    Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.... Read more

    Affected Products : comdev_ecommerce
    • EPSS Score: %0.33
    • Published: Jul. 05, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291890 Results