Total
29929 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2004-1797 | 1 Freznoshop | 1 Freznoshop | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |||||
| CVE-2004-1796 | 1 Hotnews | 1 Hotnews | 2026-06-16 | 7.5 HIGH | N/A |
| PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3. | |||||
| CVE-2004-1795 | 1 Info Touch | 1 Surfnet | 2026-06-16 | 2.1 LOW | N/A |
| Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI. | |||||
| CVE-2004-1794 | 1 Vcard4j | 1 Vcard4j | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard. | |||||
| CVE-2004-1793 | 1 Yatsoft | 1 Switch Off | 2026-06-16 | 7.5 HIGH | N/A |
| Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm. | |||||
| CVE-2004-1792 | 1 Yatsoft | 1 Switch Off | 2026-06-16 | 5.0 MEDIUM | N/A |
| swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000). | |||||
| CVE-2004-1791 | 1 Edimax | 1 Full Rate Adsl Router | 2026-06-16 | 7.5 HIGH | N/A |
| The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access. | |||||
| CVE-2004-1790 | 1 Edimax | 1 Full Rate Adsl Router | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL. | |||||
| CVE-2004-1789 | 1 Zyxel | 1 Zywall10 | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page. | |||||
| CVE-2004-1788 | 1 Asp-nuke | 1 Asp-nuke | 2026-06-16 | 5.0 MEDIUM | N/A |
| ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb. | |||||
| CVE-2004-1787 | 1 Postnuke Software Foundation | 1 Postcalendar | 2026-06-16 | 7.5 HIGH | N/A |
| SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries. | |||||
| CVE-2004-1786 | 1 Iatek | 1 Portalapp | 2026-06-16 | 5.0 MEDIUM | N/A |
| PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb. | |||||
| CVE-2004-1785 | 1 Invision Power Services | 1 Invision Board | 2026-06-16 | 7.5 HIGH | N/A |
| SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable. | |||||
| CVE-2004-1784 | 1 Webcam Corp | 1 Webcam Watchdog | 2026-06-16 | 7.5 HIGH | N/A |
| Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |||||
| CVE-2004-1783 | 1 Net2soft | 1 Flash Ftp Server | 2026-06-16 | 7.5 HIGH | N/A |
| Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot). | |||||
| CVE-2004-1782 | 1 David Maciejak | 1 Athena Web Registration | 2026-06-16 | 7.5 HIGH | N/A |
| athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter. | |||||
| CVE-2004-1781 | 1 Info Touch | 1 Surfnet | 2026-06-16 | 4.6 MEDIUM | N/A |
| Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command. | |||||
| CVE-2004-1780 | 1 Info Touch | 1 Surfnet | 2026-06-16 | 4.6 MEDIUM | N/A |
| Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts. | |||||
| CVE-2004-1779 | 1 Thwboard | 1 Thwboard Beta | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter. | |||||
| CVE-2004-1776 | 1 Cisco | 1 Ios | 2026-06-16 | 7.5 HIGH | N/A |
| Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard. | |||||
