Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2009-1495
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d…
Web File Explorer
No fix yet
MEDIUM 5.0
CVE-2008-6770EPSS 6%
YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a data…
Yourplace
after 1.0.2
MEDIUM 5.0
CVE-2008-6771EPSS 6%
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/…
Yourplace
after 1.0.2
MEDIUM 5.0
CVE-2008-6774
internettoolbar/edit.php in YourPlace 1.0.2 and earlier does not end execution when an invalid username is detected, which allows remote attackers to…
Yourplace
after 1.0.2
HIGH 7.2
CVE-2009-1462
The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent wit…
Razorcms
after 0.3
MEDIUM 5.0
CVE-2008-6755
ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier…
Zoneminder
Patch available
MEDIUM 6.8
CVE-2008-6747
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of t…
Dotproject
after 2.1.1
MEDIUM 6.4
CVE-2008-6736
Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, …
Flat Calendar
No fix yet
MEDIUM 5.0
CVE-2009-1322
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a…
Asp Product Catalog
No fix yet
HIGH 7.5
CVE-2008-6701
NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, w…
Ngenius Infinistream
Mitigation only
HIGH 7.5
CVE-2008-6673
asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change …
Quickersite
No fix yet
MEDIUM 5.0
CVE-2008-6674
mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmai…
Quickersite
No fix yet
MEDIUM 5.0
CVE-2008-6643
LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass in…
Lokicms
No fix yet
MEDIUM 5.0
CVE-2008-6650
del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vuln…
Minibloggie
No fix yet
MEDIUM 6.8
CVE-2008-6617
Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a …
Sitexs Cms
No fix yet
MEDIUM 6.8
CVE-2008-6619
Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file …
Classsystem
No fix yet
HIGH 7.5
CVE-2008-6613
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct req…
Minimal Ablog
No fix yet
MEDIUM 5.0
CVE-2008-6599
cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtai…
Cookiecheck
Patch available
MEDIUM 6.8
CVE-2008-6603
MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended…
Moinmoin
No fix yet
HIGH 7.2
CVE-2009-1235
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, w…
Mac Os X
after 10.5.6
MEDIUM 5.0
CVE-2003-1571
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…
Web Wiz Guestbook
No fix yet
MEDIUM 5.0
CVE-2008-6580
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote atta…
Red Reservations
No fix yet
MEDIUM 5.0
CVE-2009-1223
aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…
Aspwebcalendar
Mitigation only
HIGH 7.5
CVE-2009-1226
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attacke…
Podcast Generator
after 1.1
MEDIUM 5.0
CVE-2005-4880
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain …
Jax Guestbook
No fix yet
MEDIUM 5.1
CVE-2008-6540
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey val…
Dotnetnuke
after 4.8.1
HIGH 7.1
CVE-2009-0637
The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers,…
iOS
Mitigation only
HIGH 7.5
CVE-2008-6535EPSS 6%
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a dire…
Paypal Estores
No fix yet
MEDIUM 5.0
CVE-2009-1085
Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain th…
Matomo
after 0.2.32
MEDIUM 6.5
CVE-2009-1077
The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresC…
Java System Identity Manager
Patch available