Vulnerabilities (CVE)

Total 370012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1049 2 Gentoo, Wordpress 2 Linux, Wordpress 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.
CVE-2007-1048 1 Phpbb Wordsearch 1 Phpbb Wordsearch 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wordsearch allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
CVE-2007-1047 1 Distributed Checksum Clearinghouse 1 Dcc 2026-06-16 7.5 HIGH N/A
Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps.
CVE-2007-1046 1 Dem Trac 1 Dem Trac 2026-06-16 5.0 MEDIUM N/A
Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.
CVE-2007-1045 1 Malbum 1 Malbum 2026-06-16 10.0 HIGH N/A
mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.
CVE-2007-1044 1 Pearson Education 1 Powerschool 2026-06-16 5.0 MEDIUM N/A
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.
CVE-2007-1043 9 Apple, Ezboo, Hp and 6 more 18 Mac Os X, Webstats, Hp-ux and 15 more 2026-06-16 7.5 HIGH N/A
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
CVE-2007-1042 1 Xpression News 1 Xpression News 2026-06-16 5.8 MEDIUM N/A
Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-1041 1 Sandh 1 News Rover 2026-06-16 9.3 HIGH N/A
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string.
CVE-2007-1040 1 Xpression News 1 Xpression News 2026-06-16 7.5 HIGH N/A
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.
CVE-2007-1039 1 Peanutkb 1 Peanut Knowledge Base 2026-06-16 10.0 HIGH N/A
Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.
CVE-2007-1038 1 Shemes.com 1 Grabit 2026-06-16 5.0 MEDIUM N/A
Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing ';' (semicolon) characters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-1037 1 Rsbr-software 1 News File Grabber 2026-06-16 9.3 HIGH N/A
Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-1036 1 Jboss 1 Jboss Application Server 2026-06-16 7.5 HIGH N/A
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
CVE-2007-1035 1 Drupal 3 Audio Module, Getid3, Mediafield Module 2026-06-16 7.5 HIGH N/A
Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.
CVE-2007-1034 1 Php-nuke 1 Emporium Module 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
CVE-2007-1033 1 Drupal 1 Secure Site Module 2026-06-16 7.5 HIGH N/A
Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.
CVE-2007-1032 1 Phpmyfaq 1 Phpmyfaq 2026-06-16 6.8 MEDIUM N/A
Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."
CVE-2007-1031 1 Spoonlabs 1 Vivvo Article Management Cms 2026-06-16 6.8 MEDIUM N/A
Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.
CVE-2007-1030 1 Niels Provos 1 Libevent 2026-06-16 7.8 HIGH N/A
Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.