Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2007-1044EPSS 9% Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name … Powerschool No fix yet Fix from $1,6002007-02-21 MEDIUM 5.0 CVE-2007-0979 Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents)… Lifetype after 1.2_beta_1 Fix from $1,6002007-02-16 MEDIUM 5.0 CVE-2006-6998 install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, whic… Deskpro Mitigation only Fix from $1,6002007-02-12 HIGH 7.8 CVE-2007-0259 Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebas… Ezboxx Portal System Mitigation only Fix from $1,9502007-01-16 HIGH 7.8 CVE-2007-0058 Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentica… Network Admission Control Manager And Server System Software after 3.6.1.1 Fix from $1,9502007-01-04 MEDIUM 5.0 CVE-2006-5858EPSS 13% Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or rea… Coldfusion after 7.0.2 Fix from $1,6002006-12-31 MEDIUM 5.0 CVE-2006-6886 phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.pri… Phpwcms No fix yet Fix from $1,6002006-12-31 MEDIUM 5.0 CVE-2006-6735 modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request … Mini Web Shop No fix yet Fix from $1,6002006-12-26 MEDIUM 5.0 CVE-2006-6637 The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true … Websphere Application Server Patch available Fix from $1,6002006-12-19 MEDIUM 5.0 CVE-2006-6457 tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and p… Tikiwiki Cms\/groupware Mitigation only Fix from $1,6002006-12-11 MEDIUM 5.0 CVE-2006-5702EPSS 53% Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-lis… Tikiwiki Cms\/groupware No fix yet Fix from $1,6002006-11-04 MEDIUM 5.0 CVE-2006-5725 The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which re… Smartgate Ssl Server Patch available Fix from $1,6002006-11-04 MEDIUM 5.0 CVE-2006-4595 muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtai… Muforum No fix yet Fix from $1,6002006-09-07 MEDIUM 5.0 CVE-2006-4223 IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors rel… Websphere Application Server after 6.0.2.11 Fix from $1,6002006-08-18 HIGH 7.5 CVE-2006-4136 Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA… Websphere Application Server after 6.1.0.0 Fix from $1,9502006-08-14 MEDIUM 5.0 CVE-2006-4006EPSS 9% The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_… Bomberclone after 0.11.6 Fix from $1,6002006-08-07 MEDIUM 5.0 CVE-2006-3561EPSS 7% BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication … Voyager 2091 Wireless Adsl Router after 3.01m Fix from $1,6002006-07-13 MEDIUM 5.0 CVE-2006-2950 Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2)… Npds after 5.10 Fix from $1,6002006-06-12 MEDIUM 5.0 CVE-2006-2535 index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-exis… Destiney Links Script Mitigation only Fix from $1,6002006-05-22 MEDIUM 5.0 CVE-2006-2356EPSS 6% NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensiti… Whatsup Professional No fix yet Fix from $1,6002006-05-15 MEDIUM 5.0 CVE-2006-2341 The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers t… Enterprise Firewall Patch available Fix from $1,6002006-05-12 MEDIUM 6.4 CVE-2006-1677 MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct … Md Pro after 1.0.75 Fix from $1,6002006-04-11 MEDIUM 6.8 CVE-2006-1367 The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a … Pebl U6 No fix yet Fix from $1,6002006-03-23 MEDIUM 5.0 CVE-2006-0861 Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a dire… Guestbox Patch available Fix from $1,6002006-02-23 MEDIUM 5.0 CVE-2006-0707 PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading… Pyblosxom after 1.3.1 Fix from $1,6002006-02-15 MEDIUM 5.0 CVE-2006-0103 TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access co… Tinyphpforum No fix yet Fix from $1,6002006-01-06 MEDIUM 5.0 CVE-2005-1754 JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument … Apache Tomcat No fix yet Fix from $1,6002005-12-31 HIGH 7.8 CVE-2005-4836 The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot… Tomcat No fix yet Fix from $1,9502005-12-31 MEDIUM 5.0 CVE-2005-4849 Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)… Derby after 10.1.1.0 Fix from $1,6002005-12-31 HIGH 7.5 CVE-2005-4875 TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo fun… TYPO3 after 3.8.0 Fix from $1,9502005-12-31