Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2006-0144
The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirect…
Pear
Patch available
HIGH 7.5
CVE-2006-0094
PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat par…
Oaboard
Mitigation only
HIGH 7.5
CVE-2006-0064
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in…
Cubecart
No fix yet
HIGH 7.5
CVE-2005-4573EPSS 12%
PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in th…
Plogger
Patch available
HIGH 7.5
CVE-2005-3859
PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id paramet…
Q News
No fix yet
HIGH 7.5
CVE-2005-3860
PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitra…
Athena Php Website Administration
No fix yet
HIGH 7.5
CVE-2005-3861
PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL …
Phpgreetz
after 0.99
HIGH 7.5
CVE-2005-3835
PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a…
Desklance
after 2.3
HIGH 7.5
CVE-2005-3775
PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname para…
Pollvote
Mitigation only
HIGH 9.3
CVE-2005-3650EPSS 6%
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote a…
First4internet Xcp Drm
Mitigation only
MEDIUM 5.1
CVE-2005-3554
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers…
Phpkit
No fix yet
MEDIUM 5.0
CVE-2005-3571
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and …
Phpcalendar
after 2.2
HIGH 7.3
CVE-2005-3302
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh fil…
Debian Linux
No fix yet
MEDIUM 5.0
CVE-2005-2703
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and poss…
Firefox
after 1.7.11
HIGH 7.5
CVE-2005-2837
Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help…
Webgui
6.7.3+
MEDIUM 5.0
CVE-2005-1527
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl…
Ubuntu Linux
after 6.4
HIGH 7.5
CVE-2005-2498EPSS 5%
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew,…
Debian Linux
after 1.1.1
HIGH 7.5
CVE-2005-1921EPSS 79%
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earl…
Xml Rpc
1.8.5 / 4.5.4+
HIGH 7.5
CVE-2005-1965
PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the L…
Siteframe
No fix yet
MEDIUM 5.0
CVE-2005-1996
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERV…
Bitrix Site Manager
Patch available
HIGH 7.5
CVE-2005-1894
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer head…
Flatnuke
Patch available
HIGH 7.5
CVE-2005-0679
PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbi…
Tell A Friend Script
after 2.7
HIGH 7.5
CVE-2005-1155EPSS 8%
The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="i…
Firefox
Patch available
HIGH 7.5
CVE-2005-0748
PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by…
Webinsta Mailing Manager
Patch available
HIGH 7.5
CVE-2005-0720
PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the …
Mcnews
Mitigation only
HIGH 7.5
CVE-2005-0103
PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifyin…
Squirrelmail
Patch available
HIGH 7.5
CVE-2004-1166EPSS 39%
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via a…
Ie
No fix yet
MEDIUM 6.8
CVE-2004-1419
PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _z…
Zeroboard
Patch available
HIGH 7.5
CVE-2004-1423EPSS 15%
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law O…
Php Calendar
after 0.10
MEDIUM 6.5
CVE-2004-0637EPSS 18%
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, whic…
Oracle8i
Patch available