Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2005-2203

    login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.... Read more

    Affected Products : phpwishlist
    • EPSS Score: %0.57
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-2201

    Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.... Read more

    • EPSS Score: %0.41
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2181

    Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.... Read more

    • EPSS Score: %0.36
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2200

    Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.... Read more

    • EPSS Score: %0.69
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2208

    PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.... Read more

    Affected Products : privashare
    • EPSS Score: %4.72
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2190

    Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp... Read more

    Affected Products : comersus_cart
    • EPSS Score: %0.43
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 3.7

    LOW
    CVE-2005-1768

    Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.10
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2199

    PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.... Read more

    Affected Products : ppa_gallery
    • EPSS Score: %2.89
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2213

    Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.... Read more

    Affected Products : mms_ripper
    • EPSS Score: %3.08
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2150

    Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog... Read more

    Affected Products : windows_2000 windows_nt
    • EPSS Score: %29.44
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2182

    Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.... Read more

    Affected Products : bt-100_firmware bt-100
    • EPSS Score: %0.39
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2184

    eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.... Read more

    Affected Products : eroom
    • EPSS Score: %0.90
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2210

    Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.... Read more

    Affected Products : internet_download_manager
    • EPSS Score: %4.79
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2206

    Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4)... Read more

    Affected Products : cartwiz
    • EPSS Score: %0.45
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2185

    eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.... Read more

    Affected Products : eroom
    • EPSS Score: %0.64
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 5.5

    MEDIUM
    CVE-2005-2209

    Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.... Read more

    Affected Products : scanshare
    • EPSS Score: %0.04
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2191

    Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to come... Read more

    Affected Products : comersus_cart
    • EPSS Score: %0.41
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2193

    SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-sup... Read more

    Affected Products : punbb
    • EPSS Score: %0.49
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2179

    PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.... Read more

    Affected Products : jaws
    • EPSS Score: %0.63
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-2202

    Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more

    • EPSS Score: %0.36
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291946 Results