DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote atta
Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remot
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and databas
Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions
Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linu
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A
Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via t
Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web sc
ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack
Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript
Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via the (1) parseQ
AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote at
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to
phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) h
class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for acce
The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which
phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which al
ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an
Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via un
Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string."
Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote atta
SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU
frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder
Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows rem
Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remo
login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a
Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote a
Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length h
Unspecified vulnerability in meindlSOFT Cute PHP Library (aka cphplib) 0.46 has unknown impact and attack vectors, relat
The data-overwrite capability of ButtUglySoftware CleanCache 2.19 does not properly overwrite data in files, which allow
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (applica
Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote
Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows re
Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remo
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaust
Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rul
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state
Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a den
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files an
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execut
Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers
Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Ge
The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users
SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insuffi
The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive inf
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started