Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2005-1420

    Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).... Read more

    Affected Products : video_cam_server
    • EPSS Score: %0.41
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-1372

    nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.... Read more

    Affected Products : netvault
    • EPSS Score: %0.19
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1826

    Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.... Read more

    Affected Products : radia_client
    • EPSS Score: %5.89
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1425

    Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.... Read more

    Affected Products : uguestbook
    • EPSS Score: %0.62
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1447

    PHP remote file inclusion vulnerability in main.php in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to execute arbitrary PHP code via the p parameter.... Read more

    Affected Products : sitepanel
    • EPSS Score: %0.89
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1440

    Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as ... Read more

    Affected Products : viart_shop_enterprise
    • EPSS Score: %3.05
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1427

    Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.... Read more

    Affected Products : uphotogallery
    • EPSS Score: %1.02
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-1423

    Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.... Read more

    Affected Products : 602lan_suite
    • EPSS Score: %3.39
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1451

    The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.... Read more

    Affected Products : serendipity
    • EPSS Score: %0.72
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1441

    Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).... Read more

    Affected Products : lotus_domino
    • EPSS Score: %1.43
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1825

    Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameter... Read more

    Affected Products : radia_client
    • EPSS Score: %21.09
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1378

    SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.... Read more

    Affected Products : phpbb_personal_notes_module
    • EPSS Score: %0.88
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-1415

    Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.... Read more

    Affected Products : secure_ftp_server
    • EPSS Score: %70.62
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1448

    Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more

    Affected Products : serendipity
    • EPSS Score: %1.01
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0157

    The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.... Read more

    Affected Products : smartlist
    • EPSS Score: %0.39
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1382

    The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.... Read more

    • EPSS Score: %45.43
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1384

    Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.... Read more

    Affected Products : phpcoin
    • EPSS Score: %1.38
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1397

    SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more

    Affected Products : php-calendar
    • EPSS Score: %2.67
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-1452

    Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."... Read more

    Affected Products : serendipity
    • EPSS Score: %0.38
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-1371

    BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.... Read more

    Affected Products : bulletproof_ftp_server
    • EPSS Score: %0.19
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291741 Results