Latest CVE Feed
-
6.1
MEDIUMCVE-2013-6880
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.... Read more
Affected Products : flashcanvas- EPSS Score: %0.66
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-6879
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.... Read more
Affected Products : mijosearch- EPSS Score: %0.41
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-6878
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to component/mijosearch/search.... Read more
Affected Products : mijosearch- EPSS Score: %0.31
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-6876
The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: this vulnerability was fixed with commit a... Read more
Affected Products : s3dvt- EPSS Score: %0.04
- Published: Apr. 06, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-6811
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management servi... Read more
- EPSS Score: %0.16
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6792
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability... Read more
Affected Products : android- EPSS Score: %2.77
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6785
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.... Read more
Affected Products : intelligent_platform_management_interface- EPSS Score: %0.50
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-6773
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges... Read more
- EPSS Score: %0.05
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6772
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking... Read more
Affected Products : splunk- EPSS Score: %0.21
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-6739
IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.... Read more
Affected Products : spss_modeler- EPSS Score: %0.08
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-6681
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability... Read more
Affected Products : tube_map- EPSS Score: %0.66
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.34
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-6461
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits... Read more
- EPSS Score: %2.05
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-6460
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents... Read more
- EPSS Score: %2.52
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-6455
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.... Read more
Affected Products : mediawiki- EPSS Score: %0.39
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-6451
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.... Read more
Affected Products : mediawiki- EPSS Score: %0.30
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-6430
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) ... Read more
Affected Products : spring_framework- EPSS Score: %0.34
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-6365
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions... Read more
- EPSS Score: %0.33
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book... Read more
- EPSS Score: %2.29
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-6362
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.... Read more
- EPSS Score: %0.45
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024