Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Powerschool MEDIUM 5.0
CVE-2007-1044EPSS 9%

Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name …

No fix yet
Fix from $1,600 2007-02-21
Lifetype MEDIUM 5.0
CVE-2007-0979

Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents)…

Fix: after 1.2_beta_1
Fix from $1,600 2007-02-16
Deskpro MEDIUM 5.0
CVE-2006-6998

install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, whic…

Mitigation only
Fix from $1,600 2007-02-12
Ezboxx Portal System HIGH 7.8
CVE-2007-0259

Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebas…

Mitigation only
Fix from $1,950 2007-01-16
Network Admission Control Manager And Server System Software HIGH 7.8
CVE-2007-0058

Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentica…

Fix: after 3.6.1.1
Fix from $1,950 2007-01-04
Coldfusion MEDIUM 5.0
CVE-2006-5858EPSS 13%

Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or rea…

Fix: after 7.0.2
Fix from $1,600 2006-12-31
Phpwcms MEDIUM 5.0
CVE-2006-6886

phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.pri…

No fix yet
Fix from $1,600 2006-12-31
Mini Web Shop MEDIUM 5.0
CVE-2006-6735

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request …

No fix yet
Fix from $1,600 2006-12-26
Websphere Application Server MEDIUM 5.0
CVE-2006-6637

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true …

Patch available
Fix from $1,600 2006-12-19
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2006-6457

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and p…

Mitigation only
Fix from $1,600 2006-12-11
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2006-5702EPSS 53%

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-lis…

No fix yet
Fix from $1,600 2006-11-04
Smartgate Ssl Server MEDIUM 5.0
CVE-2006-5725

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which re…

Patch available
Fix from $1,600 2006-11-04
Muforum MEDIUM 5.0
CVE-2006-4595

muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtai…

No fix yet
Fix from $1,600 2006-09-07
Websphere Application Server MEDIUM 5.0
CVE-2006-4223

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors rel…

Fix: after 6.0.2.11
Fix from $1,600 2006-08-18
Websphere Application Server HIGH 7.5
CVE-2006-4136

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA…

Fix: after 6.1.0.0
Fix from $1,950 2006-08-14
Bomberclone MEDIUM 5.0
CVE-2006-4006EPSS 9%

The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_…

Fix: after 0.11.6
Fix from $1,600 2006-08-07
Voyager 2091 Wireless Adsl Router MEDIUM 5.0
CVE-2006-3561EPSS 7%

BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication …

Fix: after 3.01m
Fix from $1,600 2006-07-13
Npds MEDIUM 5.0
CVE-2006-2950

Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2)…

Fix: after 5.10
Fix from $1,600 2006-06-12
Destiney Links Script MEDIUM 5.0
CVE-2006-2535

index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-exis…

Mitigation only
Fix from $1,600 2006-05-22
Whatsup Professional MEDIUM 5.0
CVE-2006-2356EPSS 6%

NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensiti…

No fix yet
Fix from $1,600 2006-05-15
Enterprise Firewall MEDIUM 5.0
CVE-2006-2341

The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers t…

Patch available
Fix from $1,600 2006-05-12
Md Pro MEDIUM 6.4
CVE-2006-1677

MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct …

Fix: after 1.0.75
Fix from $1,600 2006-04-11
Pebl U6 MEDIUM 6.8
CVE-2006-1367

The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a …

No fix yet
Fix from $1,600 2006-03-23
Guestbox MEDIUM 5.0
CVE-2006-0861

Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a dire…

Patch available
Fix from $1,600 2006-02-23
Pyblosxom MEDIUM 5.0
CVE-2006-0707

PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading…

Fix: after 1.3.1
Fix from $1,600 2006-02-15
Tinyphpforum MEDIUM 5.0
CVE-2006-0103

TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access co…

No fix yet
Fix from $1,600 2006-01-06
Apache Tomcat MEDIUM 5.0
CVE-2005-1754

JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument …

No fix yet
Fix from $1,600 2005-12-31
Tomcat HIGH 7.8
CVE-2005-4836

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…

No fix yet
Fix from $1,950 2005-12-31
Derby MEDIUM 5.0
CVE-2005-4849

Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)…

Fix: after 10.1.1.0
Fix from $1,600 2005-12-31
TYPO3 HIGH 7.5
CVE-2005-4875

TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo fun…

Fix: after 3.8.0
Fix from $1,950 2005-12-31