Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request wi
SQL injection vulnerability in page.php in Komodo CMS 2.1 allows remote attackers to execute arbitrary SQL commands via
roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers
Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via
Directory traversal vulnerability in Amaxus 3 and earlier allows remote attackers to access arbitrary files via ".." seq
search.cfm in CONTENS 3.0 and earlier allows remote attackers to obtain the full server path via invalid (1) submit.y, (
redqueen.cgi in Red Queen 1.02 and earlier allows remote attackers to obtain the full server path via invalid (1) yellow
The 802.1q VLAN protocol allows remote attackers to bypass network segmentation and spoof VLAN traffic via a message wit
The PVLAN protocol allows remote attackers to bypass network segmentation and spoof PVLAN traffic via a PVLAN message wi
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to r
Information Call Center stores the CallCenterData.mdb database under the web root with insufficient access control, whic
cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the X
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/v
Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read
POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cau
Unspecified vulnerability in Macromedia JRun 4 web server (JWS) allows remote attackers to view web application source c
httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via
A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other
Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a
Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files vi
The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious token
Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack ve
CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct H
Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensiti
Mantis 1.0.0rc3 does not properly handle "Make note private" when a bug is being resolved, which has unknown impact and
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 b
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0
The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attac
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invali
Multiple HTTP response splitting vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 0
BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign
The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compres
The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS pac
The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compres
ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view othe
JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a f
Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary file
Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of servic
Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to cause a denial of service (infinite recursion)
The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Serv
Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a J
The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service
nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on fi
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextra
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attacker
Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm
Scan for 2005 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started