Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,516 results · Page 95/131
5.0
CVE-2007-2382

The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, whi

5.0
CVE-2007-2383

The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an

5.0
CVE-2007-2385

The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme,

5.0
CVE-2007-2415

Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOT

5.0
CVE-2007-2425

Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a

5.0
CVE-2007-2471

Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar

5.0
CVE-2007-2486

Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read

5.0
CVE-2007-2550

Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP hea

5.0
CVE-2007-2552

The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and poss

5.0
CVE-2007-2560

Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrar

5.0
CVE-2007-2566

The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of servic

5.0
CVE-2007-2574

Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary fil

5.0
CVE-2007-0244

pptpgre.c in PoPToP Point to Point Tunneling Server (pptpd) before 1.3.4 allows remote attackers to cause a denial of se

5.0
CVE-2007-2589

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attack

5.0
CVE-2007-2637

MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to rea

5.0
CVE-2007-2643

Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to

5.0
CVE-2007-0689

MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) ima

5.0
CVE-2007-2659

Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to

5.0
CVE-2007-2698

The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration cre

5.0
CVE-2007-2440

Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allo

5.0
CVE-2007-2441

Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the sys

5.0
CVE-2007-2445

The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to ca

5.0
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vect

5.0
CVE-2007-2747

Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary

5.0
CVE-2007-2749

SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar

5.0
CVE-2007-2753

RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all

5.0
CVE-2007-2684

Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b

5.0
CVE-2007-2780

PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with

5.0
CVE-2007-2786

Ratbox IRC Daemon (aka ircd-ratbox) 2.2.5 and earlier allows remote attackers to cause a denial of service (resource exh

5.0
CVE-2006-3894

The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other

5.0
CVE-2006-7205

The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a den

5.0
CVE-2007-2829

The 802.11 network stack in net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows remote attackers to cause a deni

5.0
CVE-2007-2830

The ath_beacon_config function in if_ath.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of servic

5.0
CVE-2007-1860

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server b

5.0
CVE-2007-2451

Unspecified vulnerability in drivers/crypto/geode-aes.c in GEODE-AES in the Linux kernel before 2.6.21.3 allows attacker

5.0
CVE-2007-2882

Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS

5.0
CVE-2007-2886

Unspecified vulnerability in the Nortel CS 1000 M media card in Enterprise VoIP-Core-CS 1000E, 1000M, and 1000S 04.50W b

5.0
CVE-2007-2903

Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (O

5.0
CVE-2007-2906

Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass

5.0
CVE-2007-2912

Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disable

5.0
CVE-2007-0690

myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.

5.0
CVE-2007-0692

DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid ne

5.0
CVE-2007-2944

WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attacke

5.0
CVE-2007-2945

RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers

5.0
CVE-2007-2964

The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial o

5.0
CVE-2007-1593

The administrative service in Symantec Veritas Volume Replicator (VVR) for Windows 3.1 through 4.3, and VVR for Unix 3.5

5.0
CVE-2007-3002

PHP JackKnife (PHPJK) allows remote attackers to obtain sensitive information via (1) a request to index.php with an inv

5.0
CVE-2007-3007

PHP 5 before 5.2.3 does not enforce the open_basedir or safe_mode restriction in certain cases, which allows context-dep

5.0
CVE-2007-1862

The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can

5.0
CVE-2007-3044

Unspecified vulnerability in the Map I/O Service (xpwmap) in Hitachi XP/W on HI-UX/WE2 before 20070319, and XP/W on HP-U

Scan for 2007 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started