Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.5

    HIGH
    CVE-2004-1364

    Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.... Read more

    • EPSS Score: %15.17
    • Published: Aug. 04, 2004
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2004-1363

    Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.... Read more

    • EPSS Score: %27.66
    • Published: Aug. 04, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-1366

    Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.... Read more

    • EPSS Score: %0.30
    • Published: Aug. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1679

    Directory traversal vulnerability in TwinFTP 1.0.3 R2 allows remote attackers to create arbitrary files via a .../ (triple dot) in the (1) CWD, (2) STOR, or (3) RETR commands.... Read more

    Affected Products : twinftp_enterprise twinftp_standard
    • EPSS Score: %3.89
    • Published: Aug. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1708

    Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.... Read more

    Affected Products : webbsyte_chat
    • EPSS Score: %0.65
    • Published: Aug. 02, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1706

    The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via an HTTP GET request with a long version string.... Read more

    Affected Products : usr808054
    • EPSS Score: %2.96
    • Published: Aug. 02, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1704

    WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.... Read more

    Affected Products : wpquiz
    • EPSS Score: %0.72
    • Published: Jul. 30, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1705

    Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.... Read more

    Affected Products : ux
    • EPSS Score: %24.08
    • Published: Jul. 30, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-1707

    The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privi... Read more

    • EPSS Score: %12.30
    • Published: Jul. 30, 2004
    • Modified: Apr. 03, 2025
  • 8.8

    HIGH
    CVE-2004-1703

    Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page... Read more

    Affected Products : fusion_news
    • EPSS Score: %0.57
    • Published: Jul. 30, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-2064

    Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.... Read more

    Affected Products : lostbook
    • EPSS Score: %0.68
    • Published: Jul. 29, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2067

    SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.... Read more

    Affected Products : jaws
    • EPSS Score: %1.91
    • Published: Jul. 29, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2066

    SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.... Read more

    Affected Products : linpha
    • EPSS Score: %0.97
    • Published: Jul. 29, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0741

    LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.... Read more

    Affected Products : www_file_share_pro
    • EPSS Score: %0.71
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0738

    Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.... Read more

    Affected Products : php-nuke
    • EPSS Score: %0.02
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 3.6

    LOW
    CVE-2004-0698

    4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.... Read more

    Affected Products : webstar
    • EPSS Score: %0.07
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2004-0725

    Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.... Read more

    Affected Products : moodle
    • EPSS Score: %1.96
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0700

    Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HT... Read more

    Affected Products : linux mod_ssl
    • EPSS Score: %30.65
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2004-0705

    Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow r... Read more

    Affected Products : bugzilla
    • EPSS Score: %0.86
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0724

    The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.... Read more

    • EPSS Score: %0.74
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291722 Results