Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

5,732 results · Page 37/115
7.5
CVE-2008-6663

SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker

7.5
CVE-2008-6664

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting

7.5
CVE-2008-6667

A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator priv

7.5
CVE-2008-6669

viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t

7.5
CVE-2008-6673

asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows re

7.5
CVE-2008-6677

Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5

7.5
CVE-2008-6678

SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrar

7.5
CVE-2007-6725

The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a

7.5
CVE-2009-1277

SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary

7.5
CVE-2009-1278

Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attacker

7.5
CVE-2009-1282

SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to e

7.5
CVE-2008-6685

Unspecified vulnerability in Frontend Filemanager (air_filemanager) 0.6.1 and earlier extension for TYPO3 allows remote

7.5
CVE-2008-6686

SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execu

7.5
CVE-2008-6689

SQL injection vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers

7.5
CVE-2008-6690

Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attack

7.5
CVE-2008-6691

SQL injection vulnerability in Diocese of Portsmouth Calendar Today (pd_calendar_today) extension 0.0.3 for TYPO3 allows

7.5
CVE-2008-6692

SQL injection vulnerability in Diocese of Portsmouth Training Courses (pd_trainingcourses) extension 0.1.1 for TYPO3 all

7.5
CVE-2008-6693

SQL injection vulnerability in Download system (sb_downloader) extension 0.1.4 and earlier for TYPO3 allows remote attac

7.5
CVE-2008-6694

SQL injection vulnerability in Random Prayer (ste_prayer) 0.0.1 for TYPO3 allows remote attackers to execute arbitrary S

7.5
CVE-2008-6695

SQL injection vulnerability in TIMTAB social bookmark icons (timtab_sociable) 2.0.4 and earlier extension for TYPO3 allo

7.5
CVE-2008-6696

SQL injection vulnerability in Fussballtippspiel (toto) 0.1.1 and earlier extension for TYPO3 allows remote attackers to

7.5
CVE-2008-6697

SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote att

7.5
CVE-2008-6701

NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en

7.5
CVE-2008-6714

admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by

7.5
CVE-2008-6716

homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows r

7.5
CVE-2008-6717

U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,

7.5
CVE-2008-6718

U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, whic

7.5
CVE-2008-6719

U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm

7.5
CVE-2008-6720

SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to

7.5
CVE-2008-6721

SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman

7.5
CVE-2008-6723

TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by

7.5
CVE-2009-0993

Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect

7.5
CVE-2009-1000

The Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 uses default passwords for un

7.5
CVE-2009-1285

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x be

7.5
CVE-2009-0946

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors re

7.5
CVE-2009-1316

Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the

7.5
CVE-2009-1319

Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute

7.5
CVE-2009-1323

SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL comman

7.5
CVE-2008-6728

SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute

7.5
CVE-2009-1345

SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL command

7.5
CVE-2009-1346

SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL comm

7.5
CVE-2009-0716

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a

7.5
CVE-2008-6738

MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce

7.5
CVE-2008-6739

Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem

7.5
CVE-2008-6741

SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec

7.5
CVE-2008-6743

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi

7.5
CVE-2009-1368

Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .

7.5
CVE-2008-6745

index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg

7.5
CVE-2009-1182

Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0

7.5
CVE-2008-6752

adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original passw

Scan for 2009 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started