Total
29998 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2005-1315 | 1 Horde | 1 Turba | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. | |||||
| CVE-2005-1314 | 1 Horde | 1 Kronolith | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. | |||||
| CVE-2005-1313 | 1 Horde | 1 Passwd | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. | |||||
| CVE-2005-1312 | 1 Yappa-ng | 1 Yappa-ng | 2026-06-16 | 7.5 HIGH | N/A |
| PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors. | |||||
| CVE-2005-1311 | 1 Yappa-ng | 1 Yappa-ng | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
| CVE-2005-1310 | 1 Eaden Mckee | 1 Bblog | 2026-06-16 | 7.5 HIGH | N/A |
| SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |||||
| CVE-2005-1309 | 1 Eaden Mckee | 1 Bblog | 2026-06-16 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text. | |||||
| CVE-2005-1308 | 1 Inter7 | 1 Sqwebmail | 2026-06-16 | 7.5 HIGH | N/A |
| SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML. | |||||
| CVE-2005-1307 | 2 Adobe, Apple | 2 Version Cue, Mac Os X | 2026-06-16 | 7.2 HIGH | N/A |
| The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory. | |||||
| CVE-2005-1305 | 1 Hyper.cgi | 1 Hyper.cgi | 2026-06-16 | 5.0 MEDIUM | N/A |
| The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | |||||
| CVE-2005-1304 | 1 Citat.pl | 1 Citat.pl | 2026-06-16 | 7.5 HIGH | N/A |
| The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument. | |||||
| CVE-2005-1303 | 1 Citat.pl | 1 Citat.pl | 2026-06-16 | 7.5 HIGH | N/A |
| The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument. | |||||
| CVE-2005-1302 | 1 Swsoft | 1 Confixx | 2026-06-16 | 7.5 HIGH | N/A |
| SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field. | |||||
| CVE-2005-1301 | 1 Nprotect | 1 Netizen | 2026-06-16 | 2.6 LOW | N/A |
| nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files. | |||||
| CVE-2005-1300 | 1 Inserter.cgi | 1 Inserter.cgi | 2026-06-16 | 6.8 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument. | |||||
| CVE-2005-1299 | 1 Inserter.cgi | 1 Inserter.cgi | 2026-06-16 | 10.0 HIGH | N/A |
| The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | |||||
| CVE-2005-1298 | 1 Inserter.cgi | 1 Inserter.cgi | 2026-06-16 | 7.5 HIGH | N/A |
| The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | |||||
| CVE-2005-1297 | 1 Include.cgi | 1 Include.cgi | 2026-06-16 | 6.8 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument. | |||||
| CVE-2005-1296 | 1 Include.cgi | 1 Include.cgi | 2026-06-16 | 7.5 HIGH | N/A |
| include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | |||||
| CVE-2005-1295 | 1 Include.cgi | 1 Include.cgi | 2026-06-16 | 7.5 HIGH | N/A |
| include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | |||||
