VulDB Updates Updates
- CVE-2025-3234 | Filester Plugin up to 1.8.8 on WordPress unrestricted upload (EUVD-2025-18320)by vuldb.com on June 14, 2025 at 7:07 am
A vulnerability classified as critical has been found in Filester Plugin up to 1.8.8 on WordPress. Affected is an unknown function. The manipulation leads to unrestricted upload. This vulnerability is traded as CVE-2025-3234. It is possible to launch the attack remotely. There is no exploit available.
- CVE-2007-2694 | BEA WebLogic Server up to 6.1 cross site scripting (ID 86766 / XFDB-34365)by vuldb.com on June 14, 2025 at 6:58 am
A vulnerability was found in BEA WebLogic Server up to 6.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The identification of this vulnerability is CVE-2007-2694. The attack may be initiated remotely. There is no exploit available.
- CVE-2007-2695 | BEA WebLogic Server up to 6.1 Remote Code Execution (ID 86766 / XFDB-34282)by vuldb.com on June 14, 2025 at 6:58 am
A vulnerability was found in BEA WebLogic Server up to 6.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to Remote Code Execution. This vulnerability is traded as CVE-2007-2695. It is possible to launch the attack remotely. There is no exploit available.
- CVE-2007-0426 | BEA WebLogic Portal 9.2 Remote Code Execution (ID 86766 / XFDB-31602)by vuldb.com on June 14, 2025 at 6:58 am
A vulnerability has been found in BEA WebLogic Portal 9.2 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to Remote Code Execution. This vulnerability is known as CVE-2007-0426. The attack can be launched remotely. There is no exploit available.
- CVE-2007-0444 | Citrix Presentation Server up to 4.0 ccprov.dll Print Request memory corruption (ID 115903 / XFDB-31751)by vuldb.com on June 14, 2025 at 6:58 am
A vulnerability has been found in Citrix Presentation Server up to 4.0 and classified as critical. Affected by this vulnerability is an unknown functionality in the library ccprov.dll. The manipulation as part of Print Request leads to memory corruption. This vulnerability is known as CVE-2007-0444. The attack can be launched remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2007-0451 | SpamAssassin up to 3.1.7 URI Long URI resource management (Nessus ID 67450 / ID 115518)by vuldb.com on June 14, 2025 at 6:58 am
A vulnerability, which was classified as problematic, was found in SpamAssassin up to 3.1.7. Affected is an unknown function of the component URI Handler. The manipulation as part of Long URI leads to improper resource management. This vulnerability is traded as CVE-2007-0451. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2007-0598 | Aztek forum 4.0 sql injection (EDB-3196 / OSVDB-33595)by vuldb.com on June 14, 2025 at 6:46 am
A vulnerability, which was classified as critical, has been found in Aztek forum 4.0. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. This vulnerability is handled as CVE-2007-0598. The attack may be launched remotely. Furthermore, there is an exploit available.
- CVE-2017-2531 | Apple Safari up to 10.1.0 WebKit memory corruption (HT207804 / EDB-42104)by vuldb.com on June 14, 2025 at 6:37 am
A vulnerability, which was classified as critical, has been found in Apple Safari up to 10.1.0. Affected by this issue is the function emitPutDerivedConstructorToArrowFunctionContextScope of the component WebKit. The manipulation leads to memory corruption. This vulnerability is handled as CVE-2017-2531. The attack may be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2025-33108 | IBM Backup Recovery and Media Services for i 7.4/7.5 unnecessary privileges (EUVD-2025-18318)by vuldb.com on June 14, 2025 at 6:22 am
A vulnerability classified as critical has been found in IBM Backup Recovery and Media Services for i 7.4/7.5. Affected is an unknown function. The manipulation leads to execution with unnecessary privileges. This vulnerability is traded as CVE-2025-33108. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2005-3963 | DotClear 1.2.1/1.2.2 session.php dc_xd sql injection (EDB-26689 / BID-15667)by vuldb.com on June 14, 2025 at 6:12 am
A vulnerability was found in DotClear 1.2.1/1.2.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file session.php. The manipulation of the argument dc_xd leads to sql injection. This vulnerability is handled as CVE-2005-3963. The attack may be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2006-5505 | Ben3w 2BGal 3.0 lang file inclusion (EDB-2698 / XFDB-29759)by vuldb.com on June 14, 2025 at 5:59 am
A vulnerability, which was classified as critical, was found in Ben3w 2BGal 3.0. This affects an unknown part. The manipulation of the argument lang leads to file inclusion. This vulnerability is uniquely identified as CVE-2006-5505. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2015-1679 | Microsoft Windows Server 2003 SP2 up to Server 2012 R2 Kernel-Mode Driver information disclosure (MS15-051 / EDB-37049)by vuldb.com on June 14, 2025 at 5:51 am
A vulnerability, which was classified as problematic, was found in Microsoft Windows. This affects an unknown part of the component Kernel-Mode Driver. The manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2015-1679. Attacking locally is a requirement. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2025-6059 | Seraphinite Solutions Seraphinite Accelerator Plugin up to 2.27.21 on WordPress OnAdminApi_CacheOpBegin cross-site request forgery (EUVD-2025-18319)by vuldb.com on June 14, 2025 at 5:20 am
A vulnerability was found in Seraphinite Solutions Seraphinite Accelerator Plugin up to 2.27.21 on WordPress. It has been declared as problematic. This vulnerability affects the function OnAdminApi_CacheOpBegin. The manipulation leads to cross-site request forgery. This vulnerability was named CVE-2025-6059. The attack can be initiated remotely. There is no exploit available.
- CVE-2011-2960 | Sunwayland ForceControl 6.1 httpsvr.exe memory corruption (EDB-35864 / SBV-31859)by vuldb.com on June 14, 2025 at 5:11 am
A vulnerability was found in Sunwayland ForceControl 6.1. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the file httpsvr.exe. The manipulation leads to memory corruption. This vulnerability is known as CVE-2011-2960. The attack can be launched remotely. Furthermore, there is an exploit available.
- CVE-2000-0835 | Sambar Server 4.3/4.4 ISAPI Search Utility search.dll Query privileges management (EDB-20223 / Nessus ID 10514)by vuldb.com on June 14, 2025 at 4:52 am
A vulnerability classified as critical has been found in Sambar Server 4.3/4.4. Affected is an unknown function in the library search.dll of the component ISAPI Search Utility. The manipulation of the argument Query leads to improper privilege management. This vulnerability is traded as CVE-2000-0835. It is possible to launch the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2004-1735 | Sympa 4.0/4.1/4.1.1/4.1.2 Description cross site scripting (EDB-24389 / Nessus ID 14323)by vuldb.com on June 14, 2025 at 4:45 am
A vulnerability classified as problematic was found in Sympa 4.0/4.1/4.1.1/4.1.2. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Description leads to basic cross site scripting. This vulnerability is known as CVE-2004-1735. The attack can be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2025-4232 | Palo Alto GlobalProtect App up to 6.0.0/6.1.0/6.2.8-h1/6.3.2 Log Collection wildcards or matching symbols (Nessus ID 238432)by vuldb.com on June 14, 2025 at 4:33 am
A vulnerability, which was classified as critical, has been found in Palo Alto GlobalProtect App up to 6.0.0/6.1.0/6.2.8-h1/6.3.2. Affected by this issue is some unknown functionality of the component Log Collection. The manipulation leads to improper neutralization of wildcards or matching symbols. This vulnerability is handled as CVE-2025-4232. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-36633 | Tenable Agent up to 10.8.4 on Windows privileges management (EUVD-2025-18279 / Nessus ID 238433)by vuldb.com on June 14, 2025 at 4:33 am
A vulnerability classified as critical was found in Tenable Agent up to 10.8.4 on Windows. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper privilege management. This vulnerability is known as CVE-2025-36633. Local access is required to approach this attack. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-36631 | Tenable Agent up to 10.8.4 on Windows privileges management (EUVD-2025-18277 / Nessus ID 238433)by vuldb.com on June 14, 2025 at 4:33 am
A vulnerability, which was classified as critical, has been found in Tenable Agent up to 10.8.4 on Windows. Affected by this issue is some unknown functionality. The manipulation leads to improper privilege management. This vulnerability is handled as CVE-2025-36631. Attacking locally is a requirement. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2002-0189 | Microsoft Internet Explorer 6.0 Local HTML HTML injection (MS02-023 / EDB-21750)by vuldb.com on June 14, 2025 at 4:27 am
A vulnerability was found in Microsoft Internet Explorer 6.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Local HTML Handler. The manipulation leads to HTML injection. This vulnerability is known as CVE-2002-0189. The attack can be launched remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2017-2531 | Apple tvOS up to 10.2.0 WebKit memory corruption (HT207801 / EDB-42104)by vuldb.com on June 14, 2025 at 4:21 am
A vulnerability was found in Apple tvOS up to 10.2.0. It has been rated as critical. Affected by this issue is the function emitPutDerivedConstructorToArrowFunctionContextScope of the component WebKit. The manipulation leads to memory corruption. This vulnerability is handled as CVE-2017-2531. The attack may be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2006-0418 | Topcmm Computing 123 Flash Chat Server 5.0 memory corruption (EDB-27121 / BID-16360)by vuldb.com on June 14, 2025 at 4:10 am
A vulnerability was found in Topcmm Computing 123 Flash Chat Server 5.0. It has been classified as critical. This affects an unknown part. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2006-0418. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2004-2702 | Swsoft Plesk 7.0/7.1 login_up.php3 login_name cross site scripting (EDB-24405 / Nessus ID 14369)by vuldb.com on June 14, 2025 at 4:01 am
A vulnerability was found in Swsoft Plesk 7.0/7.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file login_up.php3. The manipulation of the argument login_name leads to cross site scripting. This vulnerability is handled as CVE-2004-2702. The attack may be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2011-4800 | Serv-U up to 7.1.0.2 path traversal (EDB-18182 / SA47021)by vuldb.com on June 14, 2025 at 3:47 am
A vulnerability was found in Serv-U. It has been classified as critical. This affects an unknown part. The manipulation leads to path traversal. This vulnerability is uniquely identified as CVE-2011-4800. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2011-2950 | RealNetworks RealPlayer up to 14.0.5 qcpfformat.dll memory corruption (EDB-17849 / Nessus ID 55908)by vuldb.com on June 14, 2025 at 3:18 am
A vulnerability was found in RealNetworks RealPlayer. It has been declared as very critical. Affected by this vulnerability is an unknown functionality in the library qcpfformat.dll. The manipulation leads to memory corruption. This vulnerability is known as CVE-2011-2950. The attack can be launched remotely. Furthermore, there is an exploit available.
- CVE-2019-19208 | Codiad Web IDE up to 2.8.4 code injection (ID 162753 / EDB-49902)by vuldb.com on June 14, 2025 at 3:02 am
A vulnerability was found in Codiad Web IDE up to 2.8.4. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to code injection. This vulnerability was named CVE-2019-19208. The attack can be initiated remotely. Furthermore, there is an exploit available.
- CVE-2002-0191 | Microsoft Internet Explorer 5.01/5.5/6.0 Stylesheet cssText File information disclosure (MS02-023 / EDB-21361)by vuldb.com on June 14, 2025 at 2:51 am
A vulnerability classified as critical has been found in Microsoft Internet Explorer 5.01/5.5/6.0. This affects an unknown part of the component Stylesheet Handler. The manipulation of the argument cssText with the input { leads to information disclosure (File). This vulnerability is uniquely identified as CVE-2002-0191. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2005-4095 | DoceboLMS 2.0.4 connector.php Type path traversal (EDB-1356 / XFDB-23518)by vuldb.com on June 14, 2025 at 2:31 am
A vulnerability classified as problematic has been found in DoceboLMS 2.0.4. Affected is an unknown function of the file connector.php. The manipulation of the argument Type leads to path traversal. This vulnerability is traded as CVE-2005-4095. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
- CVE-2013-4147 | YARD RADIUS 1.1.2-4 log.c build_version format string (EDB-38672 / XFDB-85892)by vuldb.com on June 14, 2025 at 2:21 am
A vulnerability was found in YARD RADIUS 1.1.2-4. It has been declared as critical. This vulnerability affects the function build_version of the file log.c. The manipulation leads to format string. This vulnerability was named CVE-2013-4147. The attack can be initiated remotely. Furthermore, there is an exploit available.
- CVE-2010-4612 | Hycus CMS 1.0.3 index.php site sql injection (EDB-15797 / XFDB-64438)by vuldb.com on June 14, 2025 at 2:13 am
A vulnerability classified as critical was found in Hycus CMS 1.0.3. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument site leads to sql injection. This vulnerability is known as CVE-2010-4612. The attack can be launched remotely. Furthermore, there is an exploit available.