Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2109 1 Wordpress 1 Wordpress 2025-04-03 5.0 MEDIUM N/A
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
CVE-2006-4240 1 Fusionphp 1 Fusion News 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
CVE-2006-4763 1 Ibm 1 Lotus Domino Web Access 2025-04-03 7.5 HIGH N/A
IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.
CVE-2005-3865 1 Scripts-templates 1 Allweb Search 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.
CVE-2005-2170 1 Ibm 1 Tivoli Management Framework 2025-04-03 5.0 MEDIUM N/A
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
CVE-2006-0983 1 David Barrett 1 Qwikiwiki 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2006-4750 1 Openi-cms Group 1 Openi-cms 2025-04-03 5.1 MEDIUM N/A
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.
CVE-2002-0533 1 Phpbb Group 1 Phpbb 2025-04-03 5.0 MEDIUM N/A
phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.
CVE-1999-0427 1 Qualcomm 3 Eudora, Eudora Light, Eudora Pro 2025-04-03 7.5 HIGH N/A
Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.
CVE-2003-0243 1 Happycgi 1 Happymall 2025-04-03 7.5 HIGH N/A
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.
CVE-2003-0734 1 Padl Software 1 Pam Ldap 2025-04-03 10.0 HIGH N/A
Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system.
CVE-2005-0595 1 Working Resources Inc. 1 Badblue 2025-04-03 7.5 HIGH N/A
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
CVE-2002-0588 1 Steve Korbett 1 Pvote 2025-04-03 5.0 MEDIUM N/A
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
CVE-2005-0501 1 Digipen Institute Of Technology 1 Bontago 2025-04-03 7.5 HIGH N/A
Buffer overflow in Bontago 1.1 and earlier allows remote attackers to execute arbitrary code via a long nickname.
CVE-2006-0939 1 Dci-designs 1 Dci-taskeen 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.
CVE-2006-1321 1 Webcheck 1 Webcheck 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.
CVE-2005-1785 1 Zongg 1 Zongg 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2002-1098 1 Cisco 2 Vpn 3000 Concentrator Series Software, Vpn 3002 Hardware Client 2025-04-03 7.5 HIGH N/A
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.
CVE-2006-2293 1 Expinion.net 1 Multicalendars 2025-04-03 6.4 MEDIUM N/A
SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2006-4127 1 Dconnect 1 Dconnect Daemon 2025-04-03 4.6 MEDIUM N/A
Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cmd.user.c, (b) penalties.c, or (c) cmd.dc.c.