Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2008-6388 Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down… Rapid Classified No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6354 The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… Aspired2poll No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6355 The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl… Aspired2protect No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6356 evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d… Evcal Events Calendar No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6357 MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow… Mycal Personal Events Calendar No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6321 CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive info… Cf Shopkart No fix yet Fix from $1,6002009-02-27 HIGH 7.5 CVE-2008-6302 TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/adm… Local Classifieds No fix yet Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6291 Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin". Acc Php Email No fix yet Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6292 Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) righ… Acc Autos No fix yet Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6293 admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie… Acc Real Estate No fix yet Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6294 admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie … Acc Statistics No fix yet Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6296 admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo." Php Shop No fix yet Fix from $1,9502009-02-26 MEDIUM 5.0 CVE-2009-0732 Downloadcenter 2.1 stores common.h under the web root with insufficient access control, which allows remote attackers to obtain user credentials and … Downloadcenter Mitigation only Fix from $1,6002009-02-24 HIGH 7.6 CVE-2007-5289EPSS 9% HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions… Mercury Quality Center after 9.2 Fix from $1,9502009-02-24 HIGH 7.2 CVE-2009-0439 Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain p… Websphere Mq Patch available Fix from $1,9502009-02-24 HIGH 9.3 CVE-2009-0641EPSS 9% sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in olde… FreeBSD Patch available Fix from $1,9502009-02-20 MEDIUM 5.0 CVE-2008-6160 Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement men… Semantically Interconnected Online Communities after 6.x_1.0 Fix from $1,6002009-02-18 MEDIUM 6.0 CVE-2009-0613 Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended pe… Interscan Web Security Suite Mitigation only Fix from $1,6002009-02-17 MEDIUM 5.0 CVE-2008-6147 ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database v… Forumapp No fix yet Fix from $1,6002009-02-16 HIGH 7.5 CVE-2008-6136 Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrat… Everyblog No fix yet Fix from $1,9502009-02-14 HIGH 7.5 CVE-2008-6137 EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors. Everyblog No fix yet Fix from $1,9502009-02-14 MEDIUM 5.0 CVE-2009-0571 admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote … Mailist No fix yet Fix from $1,6002009-02-13 MEDIUM 6.5 CVE-2008-6125 Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to … Moodle 1.6.6 / 1.7.3+ Fix from $1,6002009-02-13 HIGH 7.2 CVE-2009-0011 Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file opera… Mac Os X Patch available Fix from $1,9502009-02-13 HIGH 7.2 CVE-2009-0436 The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Ser… Websphere Application Server Patch available Fix from $1,9502009-02-10 MEDIUM 5.0 CVE-2009-0438 IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive in… Websphere Application Server Patch available Fix from $1,6002009-02-10 HIGH 7.5 CVE-2009-0469 Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vector… Fulltext Search Cgi No fix yet Fix from $1,9502009-02-10 MEDIUM 5.0 CVE-2009-0498 Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow… Virtual Guestbook No fix yet Fix from $1,6002009-02-10 HIGH 7.2 CVE-2009-0477 Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via ve… Opensolaris No fix yet Fix from $1,9502009-02-08 MEDIUM 5.1 CVE-2008-6065 Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTO… Database Server Mitigation only Fix from $1,6002009-02-05