Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.8

    MEDIUM
    CVE-2005-1444

    Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid para... Read more

    Affected Products : sitepanel
    • EPSS Score: %2.08
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-1371

    BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.... Read more

    Affected Products : bulletproof_ftp_server
    • EPSS Score: %0.19
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1378

    SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.... Read more

    Affected Products : phpbb_personal_notes_module
    • EPSS Score: %0.88
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-1452

    Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."... Read more

    Affected Products : serendipity
    • EPSS Score: %0.38
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1451

    The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.... Read more

    Affected Products : serendipity
    • EPSS Score: %0.72
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1427

    Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.... Read more

    Affected Products : uphotogallery
    • EPSS Score: %1.02
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1440

    Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as ... Read more

    Affected Products : viart_shop_enterprise
    • EPSS Score: %3.05
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-1423

    Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.... Read more

    Affected Products : 602lan_suite
    • EPSS Score: %3.39
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1441

    Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).... Read more

    Affected Products : lotus_domino
    • EPSS Score: %1.43
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-1379

    The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.... Read more

    Affected Products : mandrake_lam-runtime
    • EPSS Score: %0.06
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1380

    Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %1.28
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1381

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.... Read more

    • EPSS Score: %26.54
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-1392

    The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.... Read more

    Affected Products : phpmyadmin
    • EPSS Score: %0.05
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1417

    Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments t... Read more

    Affected Products : maxwebportal
    • EPSS Score: %0.45
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1443

    Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.... Read more

    Affected Products : invision_power_board
    • EPSS Score: %1.04
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1374

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php... Read more

    Affected Products : claroline
    • EPSS Score: %2.57
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1373

    Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.... Read more

    Affected Products : koobi_cms
    • EPSS Score: %1.04
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1435

    Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.... Read more

    Affected Products : open_webmail
    • EPSS Score: %1.32
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-1436

    Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4)... Read more

    Affected Products : osticket
    • EPSS Score: %2.08
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1438

    PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.... Read more

    Affected Products : osticket
    • EPSS Score: %0.72
    • Published: May. 03, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291782 Results