Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Phpbb Auction MEDIUM 6.8
CVE-2006-2245EPSS 8%

PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP …

Mitigation only
Fix from $1,600 2006-05-09
Coolmenus MEDIUM 6.8
CVE-2006-2122

PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter. …

Mitigation only
Fix from $1,600 2006-05-01
Myevent HIGH 7.5
CVE-2006-1890

Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the mye…

No fix yet
Fix from $1,950 2006-04-20
Phpbb MEDIUM 6.0
CVE-2006-1896

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font …

Patch available
Fix from $1,600 2006-04-20
Monster Top List HIGH 7.5
CVE-2006-1781EPSS 10%

PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code…

Fix: after 1.4.2
Fix from $1,950 2006-04-13
Phplistpro HIGH 7.5
CVE-2006-1749EPSS 8%

PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the ret…

Fix: after 2.0
Fix from $1,950 2006-04-12
Squery HIGH 7.5
CVE-2006-1688EPSS 7%

Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote at…

Fix: after 4.5
Fix from $1,950 2006-04-11
Virtual War HIGH 7.5
CVE-2006-1636

PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a U…

Patch available
Fix from $1,950 2006-04-06
Squery MEDIUM 5.1
CVE-2006-1610EPSS 7%

PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows…

Fix: after 4.5
Fix from $1,600 2006-04-04
Office HIGH 9.3
CVE-2006-1540EPSS 29%

MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary…

No fix yet
Fix from $1,950 2006-03-30
Virtual War MEDIUM 5.1
CVE-2006-1503

PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to incl…

No fix yet
Fix from $1,600 2006-03-30
Application Framework HIGH 7.5
CVE-2006-1491EPSS 38%

Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2006-03-29
Cms HIGH 9.0
CVE-2006-1371EPSS 9%

Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and…

Fix: after 0.5
Fix from $1,950 2006-03-23
Ie HIGH 9.3
CVE-2006-1359EPSS 68%

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain cre…

No fix yet
Fix from $1,950 2006-03-23
Sa Exim MEDIUM 5.0
CVE-2006-1251

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field …

Patch available
Fix from $1,600 2006-03-19
Mac Os X HIGH 7.5
CVE-2006-0397

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0398

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0399

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Fantastic News HIGH 7.5
CVE-2006-1154

PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[scri…

No fix yet
Fix from $1,950 2006-03-10
Igenus Webmail HIGH 7.5
CVE-2006-1031

config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.

No fix yet
Fix from $1,950 2006-03-07
Sap Web Application Server MEDIUM 6.4
CVE-2006-1039

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive au…

Mitigation only
Fix from $1,600 2006-03-07
Weblog MEDIUM 6.5
CVE-2006-0945

PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary …

Mitigation only
Fix from $1,600 2006-03-01
Phplib HIGH 7.5
CVE-2006-0887

Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on t…

Patch available
Fix from $1,950 2006-02-25
Iuser Ecommerce HIGH 7.5
CVE-2006-0854

PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL…

No fix yet
Fix from $1,950 2006-02-23
Plume Cms MEDIUM 6.8
CVE-2006-0725

PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbit…

Mitigation only
Fix from $1,600 2006-02-16
Runcms MEDIUM 6.8
CVE-2006-0659

Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers…

Fix: after 1.2
Fix from $1,600 2006-02-13
Loudblog HIGH 7.5
CVE-2006-0565EPSS 9%

PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code v…

Fix: after 0.4
Fix from $1,950 2006-02-06
Ecartis MEDIUM 6.4
CVE-2006-0332

Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload…

Patch available
Fix from $1,600 2006-01-21
Htmltonuke HIGH 7.5
CVE-2006-0308

PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote…

No fix yet
Fix from $1,950 2006-01-19
Thunderbird MEDIUM 5.1
CVE-2006-0236

GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an a…

Patch available
Fix from $1,600 2006-01-18