Latest CVE Feed
-
6.5
MEDIUMCVE-2013-6460
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents... Read more
- EPSS Score: %2.52
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-6455
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.... Read more
Affected Products : mediawiki- EPSS Score: %0.39
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-6451
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.... Read more
Affected Products : mediawiki- EPSS Score: %0.30
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-6430
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) ... Read more
Affected Products : spring_framework- EPSS Score: %0.34
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-6365
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions... Read more
- EPSS Score: %0.33
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book... Read more
- EPSS Score: %2.29
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6362
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.... Read more
- EPSS Score: %0.45
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %0.21
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2013-6358
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.... Read more
Affected Products : prestashop- EPSS Score: %4.22
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6295
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module... Read more
Affected Products : prestashop- EPSS Score: %0.32
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %0.29
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6276
QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active model... Read more
- EPSS Score: %0.40
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-6275
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.... Read more
- EPSS Score: %1.94
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-6272
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangu... Read more
Affected Products : android- EPSS Score: %0.14
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-6242
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabi... Read more
Affected Products : open-xchange_appsuite- EPSS Score: %0.75
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-6239
Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter in a detail action.... Read more
Affected Products : exis_contexis- EPSS Score: %0.82
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGH- EPSS Score: %43.57
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2013-6234
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an u... Read more
Affected Products : spagobi- EPSS Score: %2.18
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2013-6231
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script... Read more
Affected Products : spagobi- EPSS Score: %35.65
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6225
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability... Read more
Affected Products : livezilla- EPSS Score: %54.06
- Published: Jan. 13, 2020
- Modified: Nov. 21, 2024