Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.8 CVE-2008-7026 Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary c… Efront after 3.5.1 Fix from $1,6002009-08-21 HIGH 10.0 CVE-2008-7010 Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/regi… Exchange Script No fix yet Fix from $1,9502009-08-19 HIGH 7.8 CVE-2009-2846EPSS 8% The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local us… Linux Kernel after 2.6.31 Fix from $1,9502009-08-18 HIGH 10.0 CVE-2009-2853 Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-… WordPress Patch available Fix from $1,9502009-08-18 MEDIUM 6.4 CVE-2009-2854 Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a d… WordPress after 2.8.2 Fix from $1,6002009-08-18 HIGH 7.5 CVE-2009-2770 PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname… Powerupload No fix yet Fix from $1,9502009-08-14 HIGH 7.5 CVE-2009-2766EPSS 5% httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remo… Dd Wrt No fix yet Fix from $1,9502009-08-14 MEDIUM 5.0 CVE-2009-2091 The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new ap… Websphere Application Server Patch available Fix from $1,6002009-08-13 HIGH 7.5 CVE-2008-6966 AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass auth… Aj Auction No fix yet Fix from $1,9502009-08-13 HIGH 7.5 CVE-2008-6963 admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request. Text Link Sales No fix yet Fix from $1,9502009-08-13 MEDIUM 5.0 CVE-2008-6960EPSS 7% download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url … X10 Automatic Mp3 Script No fix yet Fix from $1,6002009-08-12 HIGH 7.5 CVE-2008-6940 TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to… Web Hosting Directory No fix yet Fix from $1,9502009-08-12 HIGH 9.0 CVE-2008-6954 The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Ch… Cobbler after 1.2.8 Fix from $1,9502009-08-12 HIGH 7.5 CVE-2008-6957 member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actio… Discuz\! No fix yet Fix from $1,9502009-08-12 MEDIUM 6.5 CVE-2008-6928 Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a fi… Complete Classifieds No fix yet Fix from $1,6002009-08-11 MEDIUM 6.5 CVE-2008-6929 Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file w… Auto Classifieds No fix yet Fix from $1,6002009-08-11 MEDIUM 6.5 CVE-2008-6930 Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with a… Real Estate No fix yet Fix from $1,6002009-08-11 MEDIUM 6.5 CVE-2008-6931 Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploadi… Phpcareers No fix yet Fix from $1,6002009-08-11 HIGH 7.5 CVE-2008-6932 Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a f… Sendit No fix yet Fix from $1,9502009-08-11 MEDIUM 5.5 CVE-2009-2737 The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check perm… Roundup Patch available Fix from $1,6002009-08-11 MEDIUM 6.8 CVE-2009-2717 The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning I… Java Se after 6 Fix from $1,6002009-08-10 MEDIUM 6.8 CVE-2009-2718 The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from th… Java Se Mitigation only Fix from $1,6002009-08-10 HIGH 10.0 CVE-2009-1896 The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an en… Openjdk after 1.6.0.0 Fix from $1,9502009-08-10 HIGH 10.0 CVE-2009-2476 The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which … Openjdk after 6 Fix from $1,9502009-08-10 HIGH 10.0 CVE-2009-2689 JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecifie… Openjdk after 6 Fix from $1,9502009-08-10 MEDIUM 5.0 CVE-2009-2690 The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-depe… Openjdk after 6 Fix from $1,6002009-08-10 MEDIUM 6.8 CVE-2008-6918 Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a fi… Theportal2 No fix yet Fix from $1,6002009-08-10 HIGH 7.5 CVE-2008-6920EPSS 5% Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an… Phpemployment No fix yet Fix from $1,9502009-08-10 HIGH 7.5 CVE-2008-6921EPSS 5% Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an e… Phpadboard No fix yet Fix from $1,9502009-08-10 MEDIUM 6.5 CVE-2008-6914 Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by u… Zeeproperty No fix yet Fix from $1,6002009-08-07