Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0562 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 7.5 HIGH N/A
The registry in Windows NT can be accessed remotely by users who are not administrators.
CVE-2002-1521 1 Mdg Computer Services 1 Web Server 4d 2025-04-03 2.1 LOW N/A
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.
CVE-2005-1789 1 India Software Solution 1 Shopping Cart 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.
CVE-2000-0188 1 Alex Heiphetz Group 1 Ezshopper 2025-04-03 7.5 HIGH N/A
EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
CVE-2004-1726 1 John Bradley 1 Xv 2025-04-03 7.5 HIGH N/A
Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.
CVE-2001-0386 1 Analogx 1 Simpleserver Www 2025-04-03 5.0 MEDIUM N/A
AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
CVE-2005-2612 1 Wordpress 1 Wordpress 2025-04-03 7.5 HIGH N/A
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
CVE-2002-0595 1 Webtrends 1 Reporting Center 2025-04-03 7.5 HIGH N/A
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
CVE-2004-0152 1 Emil 1 Emil 2025-04-03 7.5 HIGH N/A
Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.
CVE-2006-2996 1 Lovecompass 1 Aepartner 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dir[data] parameter.
CVE-2005-2196 1 Apple 1 Airport Card 2025-04-03 2.1 LOW N/A
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.
CVE-2006-2617 1 Alstrasoft 1 Webhost Directory 2025-04-03 5.0 MEDIUM N/A
(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection.
CVE-2006-0055 1 Freebsd 1 Freebsd 2025-04-03 2.1 LOW N/A
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
CVE-2004-2439 1 Hp 17 Color Laserjet, Color Laserjet 4600, Laserjet 2500 and 14 more 2025-04-03 5.0 MEDIUM N/A
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
CVE-2005-1716 1 Ej3 1 Topo 2025-04-03 5.0 MEDIUM N/A
TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.
CVE-2003-0484 1 Phpbb Group 1 Phpbb 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.
CVE-2005-3539 1 Hylafax 1 Hylafax 2025-04-03 7.5 HIGH N/A
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
CVE-2006-3012 1 Eschew.net 1 Phpbannerexchange 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php.
CVE-2006-2533 1 Greg Donald 1 Destiney Rated Images Script 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2) leaveComments.php in Destiney Rated Images Script 0.5.0 does not properly filter all vulnerable HTML tags, which allows remote attackers to inject arbitrary web script or HTML via Javascript in a DIV tag.
CVE-2006-0428 1 Oracle 1 Weblogic Portal 2025-04-03 7.5 HIGH N/A
Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.