Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2007-1044EPSS 9%
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name …
Powerschool
No fix yet
MEDIUM 5.0
CVE-2007-0979
Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents)…
Lifetype
after 1.2_beta_1
MEDIUM 5.0
CVE-2006-6998
install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, whic…
Deskpro
Mitigation only
HIGH 7.8
CVE-2007-0259
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebas…
Ezboxx Portal System
Mitigation only
HIGH 7.8
CVE-2007-0058
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentica…
Network Admission Control Manager And Server System Software
after 3.6.1.1
MEDIUM 5.0
CVE-2006-5858EPSS 13%
Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or rea…
Coldfusion
after 7.0.2
MEDIUM 5.0
CVE-2006-6886
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.pri…
Phpwcms
No fix yet
MEDIUM 5.0
CVE-2006-6735
modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request …
Mini Web Shop
No fix yet
MEDIUM 5.0
CVE-2006-6637
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true …
Websphere Application Server
Patch available
MEDIUM 5.0
CVE-2006-6457
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and p…
Tikiwiki Cms\/groupware
Mitigation only
MEDIUM 5.0
CVE-2006-5702EPSS 53%
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-lis…
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.0
CVE-2006-5725
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which re…
Smartgate Ssl Server
Patch available
MEDIUM 5.0
CVE-2006-4595
muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtai…
Muforum
No fix yet
MEDIUM 5.0
CVE-2006-4223
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors rel…
Websphere Application Server
after 6.0.2.11
HIGH 7.5
CVE-2006-4136
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA…
Websphere Application Server
after 6.1.0.0
MEDIUM 5.0
CVE-2006-4006EPSS 9%
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_…
Bomberclone
after 0.11.6
MEDIUM 5.0
CVE-2006-3561EPSS 7%
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication …
Voyager 2091 Wireless Adsl Router
after 3.01m
MEDIUM 5.0
CVE-2006-2950
Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2)…
Npds
after 5.10
MEDIUM 5.0
CVE-2006-2535
index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-exis…
Destiney Links Script
Mitigation only
MEDIUM 5.0
CVE-2006-2356EPSS 6%
NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensiti…
Whatsup Professional
No fix yet
MEDIUM 5.0
CVE-2006-2341
The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers t…
Enterprise Firewall
Patch available
MEDIUM 6.4
CVE-2006-1677
MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct …
Md Pro
after 1.0.75
MEDIUM 6.8
CVE-2006-1367
The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a …
Pebl U6
No fix yet
MEDIUM 5.0
CVE-2006-0861
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a dire…
Guestbox
Patch available
MEDIUM 5.0
CVE-2006-0707
PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading…
Pyblosxom
after 1.3.1
MEDIUM 5.0
CVE-2006-0103
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access co…
Tinyphpforum
No fix yet
MEDIUM 5.0
CVE-2005-1754
JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument …
Apache Tomcat
No fix yet
HIGH 7.8
CVE-2005-4836
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2005-4849
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)…
Derby
after 10.1.1.0
HIGH 7.5
CVE-2005-4875
TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo fun…
TYPO3
after 3.8.0