Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2005-0478

    Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.... Read more

    Affected Products : trackercam
    • EPSS Score: %65.48
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0484

    Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.... Read more

    Affected Products : gproftpd
    • EPSS Score: %2.50
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-0474

    SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.... Read more

    Affected Products : webcalendar
    • EPSS Score: %0.56
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0477

    Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set... Read more

    Affected Products : invision_power_board
    • EPSS Score: %0.55
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0483

    Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read ... Read more

    Affected Products : glftpd
    • EPSS Score: %0.69
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0481

    TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.... Read more

    Affected Products : trackercam
    • EPSS Score: %0.50
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-0475

    SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) sear... Read more

    Affected Products : pafaq
    • EPSS Score: %0.33
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-0485

    Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.... Read more

    Affected Products : panews
    • EPSS Score: %1.09
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0486

    Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attack... Read more

    • EPSS Score: %0.52
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2005-0487

    Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.... Read more

    Affected Products : esupport
    • EPSS Score: %0.98
    • Published: Mar. 30, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0924

    Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword.... Read more

    Affected Products : e-data
    • EPSS Score: %0.68
    • Published: Mar. 29, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0919

    Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.... Read more

    Affected Products : adventia_chat adventia_server_pro
    • EPSS Score: %0.68
    • Published: Mar. 29, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0931

    PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.... Read more

    Affected Products : the_includer
    • EPSS Score: %1.72
    • Published: Mar. 29, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0950

    Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.... Read more

    Affected Products : 4in1_browser
    • EPSS Score: %7.77
    • Published: Mar. 29, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0946

    SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the... Read more

    Affected Products : phpcoin
    • EPSS Score: %0.49
    • Published: Mar. 29, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0908

    Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php.... Read more

    Affected Products : valdersoft_shopping_cart
    • EPSS Score: %0.33
    • Published: Mar. 28, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0911

    Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle action for index.php.... Read more

    Affected Products : e-xoops
    • EPSS Score: %0.43
    • Published: Mar. 28, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-0892

    Buffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM command and possibly other SMTP commands.... Read more

    Affected Products : smail
    • EPSS Score: %3.99
    • Published: Mar. 28, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-0750

    The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.... Read more

    • EPSS Score: %0.20
    • Published: Mar. 27, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0914

    Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat parameter.... Read more

    Affected Products : cpg_dragonfly_cms
    • EPSS Score: %0.28
    • Published: Mar. 26, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 292485 Results