Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Efront MEDIUM 6.8
CVE-2008-7026

Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary c…

Fix: after 3.5.1
Fix from $1,600 2009-08-21
Exchange Script HIGH 10.0
CVE-2008-7010

Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/regi…

No fix yet
Fix from $1,950 2009-08-19
Linux Kernel HIGH 7.8
CVE-2009-2846EPSS 8%

The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local us…

Fix: after 2.6.31
Fix from $1,950 2009-08-18
WordPress HIGH 10.0
CVE-2009-2853

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-…

Patch available
Fix from $1,950 2009-08-18
WordPress MEDIUM 6.4
CVE-2009-2854

Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a d…

Fix: after 2.8.2
Fix from $1,600 2009-08-18
Powerupload HIGH 7.5
CVE-2009-2770

PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname…

No fix yet
Fix from $1,950 2009-08-14
Dd Wrt HIGH 7.5
CVE-2009-2766EPSS 5%

httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remo…

No fix yet
Fix from $1,950 2009-08-14
Websphere Application Server MEDIUM 5.0
CVE-2009-2091

The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new ap…

Patch available
Fix from $1,600 2009-08-13
Aj Auction HIGH 7.5
CVE-2008-6966

AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass auth…

No fix yet
Fix from $1,950 2009-08-13
Text Link Sales HIGH 7.5
CVE-2008-6963

admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request.

No fix yet
Fix from $1,950 2009-08-13
X10 Automatic Mp3 Script MEDIUM 5.0
CVE-2008-6960EPSS 7%

download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url …

No fix yet
Fix from $1,600 2009-08-12
Web Hosting Directory HIGH 7.5
CVE-2008-6940

TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to…

No fix yet
Fix from $1,950 2009-08-12
Cobbler HIGH 9.0
CVE-2008-6954

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Ch…

Fix: after 1.2.8
Fix from $1,950 2009-08-12
Discuz\! HIGH 7.5
CVE-2008-6957

member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actio…

No fix yet
Fix from $1,950 2009-08-12
Complete Classifieds MEDIUM 6.5
CVE-2008-6928

Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a fi…

No fix yet
Fix from $1,600 2009-08-11
Auto Classifieds MEDIUM 6.5
CVE-2008-6929

Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file w…

No fix yet
Fix from $1,600 2009-08-11
Real Estate MEDIUM 6.5
CVE-2008-6930

Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with a…

No fix yet
Fix from $1,600 2009-08-11
Phpcareers MEDIUM 6.5
CVE-2008-6931

Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploadi…

No fix yet
Fix from $1,600 2009-08-11
Sendit HIGH 7.5
CVE-2008-6932

Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a f…

No fix yet
Fix from $1,950 2009-08-11
Roundup MEDIUM 5.5
CVE-2009-2737

The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check perm…

Patch available
Fix from $1,600 2009-08-11
Java Se MEDIUM 6.8
CVE-2009-2717

The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning I…

Fix: after 6
Fix from $1,600 2009-08-10
Java Se MEDIUM 6.8
CVE-2009-2718

The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from th…

Mitigation only
Fix from $1,600 2009-08-10
Openjdk HIGH 10.0
CVE-2009-1896

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an en…

Fix: after 1.6.0.0
Fix from $1,950 2009-08-10
Openjdk HIGH 10.0
CVE-2009-2476

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which …

Fix: after 6
Fix from $1,950 2009-08-10
Openjdk HIGH 10.0
CVE-2009-2689

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecifie…

Fix: after 6
Fix from $1,950 2009-08-10
Openjdk MEDIUM 5.0
CVE-2009-2690

The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-depe…

Fix: after 6
Fix from $1,600 2009-08-10
Theportal2 MEDIUM 6.8
CVE-2008-6918

Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a fi…

No fix yet
Fix from $1,600 2009-08-10
Phpemployment HIGH 7.5
CVE-2008-6920EPSS 5%

Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an…

No fix yet
Fix from $1,950 2009-08-10
Phpadboard HIGH 7.5
CVE-2008-6921EPSS 5%

Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an e…

No fix yet
Fix from $1,950 2009-08-10
Zeeproperty MEDIUM 6.5
CVE-2008-6914

Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by u…

No fix yet
Fix from $1,600 2009-08-07