Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2005-4250

    Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.... Read more

    Affected Products : mcgallery_pro
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4223

    Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster... Read more

    Affected Products : utopia_news_pro
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4226

    Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters... Read more

    Affected Products : phpwebthings
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4232

    SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and di... Read more

    Affected Products : jamit_job_board
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4229

    Cross-site scripting (XSS) vulnerability in auction.pl in EveryAuction 1.53 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. NOTE: the provenance of this issue is unknown; the details were obtaine... Read more

    Affected Products : everyauction
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4244

    SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.... Read more

    Affected Products : snipe_gallery
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4221

    SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).... Read more

    Affected Products : arab_portal
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4217

    Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.... Read more

    Affected Products : mac_os_x_server
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2831

    Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use ... Read more

    Affected Products : internet_explorer ie
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4227

    Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_m... Read more

    Affected Products : dcp-portal
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4225

    Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameter... Read more

    Affected Products : mybloggie
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4252

    Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.... Read more

    Affected Products : mcgallery_pro
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4222

    Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.... Read more

    Affected Products : guestserver
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4251

    Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.... Read more

    Affected Products : mcgallery_pro
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4230

    SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.... Read more

    Affected Products : link_up_gold
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-2827

    The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wron... Read more

    Affected Products : windows_2000 windows_nt
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-3352

    Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.... Read more

    Affected Products : http_server
    • Published: Dec. 13, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4199

    Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcode... Read more

    Affected Products : mybb
    • Published: Dec. 13, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4197

    tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.... Read more

    Affected Products : ssl_vpn
    • Published: Dec. 13, 2005
    • Modified: Apr. 03, 2025
  • 6.1

    MEDIUM
    CVE-2005-4206

    Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loa... Read more

    Affected Products : academic_suite
    • Published: Dec. 13, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 294863 Results