Vulnerabilities (CVE)

Total 398493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-1753 1 Emn 1 Coccinelle 2026-06-16 3.3 LOW N/A
Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."
CVE-2009-1752 1 Exjune 1 Office Message System 2026-06-16 7.5 HIGH N/A
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information.
CVE-2009-1751 1 Realtywebware 1 Realty Web-base 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-1750 1 Omnisoftsol 1 Vidsharepro 2026-06-16 6.0 MEDIUM N/A
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
CVE-2009-1749 1 Joost Horward 1 Catviz 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.
CVE-2009-1748 1 Joost Horward 1 Catviz 2026-06-16 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.
CVE-2009-1747 1 26thavenue 1 Bspeak 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action.
CVE-2009-1746 1 Diangemilang 1 Dgnews 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
CVE-2009-1745 1 Armorlogic 1 Profense Web Application Firewall 2026-06-16 10.0 HIGH N/A
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access.
CVE-2009-1744 1 Pinnaclesys 1 Pinnacle Studio 2026-06-16 4.3 MEDIUM N/A
InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash) via a crafted Hollywood FX Compressed Archive (.hfz) file.
CVE-2009-1743 1 Pinnaclesys 2 Pinnacle Hollywood Effects, Pinnacle Studio 2026-06-16 9.3 HIGH N/A
Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to create and overwrite arbitrary files via a filename containing a ..\ (dot dot backslash) sequence in a Hollywood FX Compressed Archive (.hfz) file. NOTE: this can be leveraged for code execution by decompressing a file to a Startup folder. NOTE: some of these details are obtained from third party information.
CVE-2009-1742 1 Pc4arb 1 Pc4 Uploader 2026-06-16 7.5 HIGH N/A
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function.
CVE-2009-1741 1 Dutchmonkey 1 Dm Filemanager 2026-06-16 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
CVE-2009-1740 1 Dlink 1 Mpeg4 Viewer Activex Control 2026-06-16 9.3 HIGH N/A
Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-1739 1 Phpeasycode 1 Pad Site Scripts 2026-06-16 7.5 HIGH N/A
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.
CVE-2009-1738 2 Drupal, Ivanjaros 2 Drupal, Feed Block 2026-06-16 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."
CVE-2009-1737 1 Diqiye 1 Mypic 2026-06-16 7.8 HIGH N/A
Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter.
CVE-2009-1736 1 Joomla 2 Com Gsticketsystem, Joomla\! 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.
CVE-2009-1735 1 Omnisoftsol 1 Vidsharepro 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. NOTE: some of these details are obtained from third party information.
CVE-2009-1734 1 Omnisoftsol 1 Vidsharepro 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter.