Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2008-7026
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary c…
Efront
after 3.5.1
HIGH 10.0
CVE-2008-7010
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/regi…
Exchange Script
No fix yet
HIGH 7.8
CVE-2009-2846EPSS 8%
The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local us…
Linux Kernel
after 2.6.31
HIGH 10.0
CVE-2009-2853
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-…
WordPress
Patch available
MEDIUM 6.4
CVE-2009-2854
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a d…
WordPress
after 2.8.2
HIGH 7.5
CVE-2009-2770
PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname…
Powerupload
No fix yet
HIGH 7.5
CVE-2009-2766EPSS 5%
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remo…
Dd Wrt
No fix yet
MEDIUM 5.0
CVE-2009-2091
The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new ap…
Websphere Application Server
Patch available
HIGH 7.5
CVE-2008-6966
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass auth…
Aj Auction
No fix yet
HIGH 7.5
CVE-2008-6963
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request.
Text Link Sales
No fix yet
MEDIUM 5.0
CVE-2008-6960EPSS 7%
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url …
X10 Automatic Mp3 Script
No fix yet
HIGH 7.5
CVE-2008-6940
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
Web Hosting Directory
No fix yet
HIGH 9.0
CVE-2008-6954
The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Ch…
Cobbler
after 1.2.8
HIGH 7.5
CVE-2008-6957
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actio…
Discuz\!
No fix yet
MEDIUM 6.5
CVE-2008-6928
Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a fi…
Complete Classifieds
No fix yet
MEDIUM 6.5
CVE-2008-6929
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file w…
Auto Classifieds
No fix yet
MEDIUM 6.5
CVE-2008-6930
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with a…
Real Estate
No fix yet
MEDIUM 6.5
CVE-2008-6931
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploadi…
Phpcareers
No fix yet
HIGH 7.5
CVE-2008-6932
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a f…
Sendit
No fix yet
MEDIUM 5.5
CVE-2009-2737
The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check perm…
Roundup
Patch available
MEDIUM 6.8
CVE-2009-2717
The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning I…
Java Se
after 6
MEDIUM 6.8
CVE-2009-2718
The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from th…
Java Se
Mitigation only
HIGH 10.0
CVE-2009-1896
The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an en…
Openjdk
after 1.6.0.0
HIGH 10.0
CVE-2009-2476
The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which …
Openjdk
after 6
HIGH 10.0
CVE-2009-2689
JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecifie…
Openjdk
after 6
MEDIUM 5.0
CVE-2009-2690
The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-depe…
Openjdk
after 6
MEDIUM 6.8
CVE-2008-6918
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a fi…
Theportal2
No fix yet
HIGH 7.5
CVE-2008-6920EPSS 5%
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an…
Phpemployment
No fix yet
HIGH 7.5
CVE-2008-6921EPSS 5%
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an e…
Phpadboard
No fix yet
MEDIUM 6.5
CVE-2008-6914
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by u…
Zeeproperty
No fix yet