Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29516 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3578 1 Walla Telesite 1 Walla Telesite 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
CVE-2006-4279 1 Xennobb 1 Xennobb 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter.
CVE-2003-0748 1 Sap 1 Internet Transaction Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.
CVE-2006-3873 1 Microsoft 4 Ie, Windows 2000, Windows 2003 Server and 1 more 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
CVE-2006-4011 1 Kayako 1 Esupport 2025-04-03 2.6 LOW N/A
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.
CVE-2002-2190 1 Artscore Studios 1 Cutecast Forum 2025-04-03 7.5 HIGH N/A
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
CVE-2006-1021 1 Pehepe 2 Membership Management System, Uyelik Sistemi 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable).
CVE-2006-4363 1 Cropimage Component 1 Cropimage Component 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.
CVE-2005-4062 1 Xcent 1 Xcclassified 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.
CVE-2002-2040 1 Qnx 1 Rtos 2025-04-03 7.2 HIGH N/A
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.
CVE-2004-2287 1 Dsm 1 Light Web File Browser 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.
CVE-2001-1097 1 Cisco 1 Ios 2025-04-03 5.0 MEDIUM N/A
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.
CVE-2003-1260 1 Globalscape 1 Cuteftp 2025-04-03 7.6 HIGH N/A
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
CVE-2005-2054 1 Realnetworks 2 Realone Player, Realplayer 2025-04-03 5.1 MEDIUM N/A
Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafted MP3 file.
CVE-2005-4505 1 Mcafee 2 Common Management Agent, Virusscan Enterprise 2025-04-03 7.2 HIGH N/A
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.
CVE-2001-0965 1 Glftpd 1 Glftpd 2025-04-03 5.0 MEDIUM N/A
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
CVE-2006-2061 1 Invision Power Services 2 Invision Board, Invision Power Board 2025-04-03 5.0 MEDIUM N/A
SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.
CVE-2005-0673 1 Phpbb Group 1 Phpbb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.
CVE-2000-0425 1 Lsoft 1 Listserv 2025-04-03 10.0 HIGH N/A
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
CVE-2000-0103 1 Netsmart 1 Smartcart 2025-04-03 7.5 HIGH N/A
The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.