Latest CVE Feed
-
6.1
MEDIUMCVE-2013-5212
Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.... Read more
Affected Products : easyxdm- EPSS Score: %0.30
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-5123
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.... Read more
- EPSS Score: %12.86
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-5122
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access... Read more
- EPSS Score: %4.10
- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2013-5116
Evernote prior to 5.5.1 has insecure password change... Read more
Affected Products : evernote- EPSS Score: %0.09
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2013-5114
LastPass prior to 2.5.1 allows secure wipe bypass.... Read more
Affected Products : lastpass- EPSS Score: %0.11
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2013-5113
LastPass prior to 2.5.1 has an insecure PIN implementation.... Read more
Affected Products : lastpass- EPSS Score: %0.12
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2013-5112
Evernote before 5.5.1 has insecure PIN storage... Read more
Affected Products : evernote- EPSS Score: %0.10
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-5106
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.... Read more
Affected Products : python-mode- EPSS Score: %0.59
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-5027
Collabtive 1.0 has incorrect access control... Read more
Affected Products : collabtive- EPSS Score: %0.36
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4985
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream... Read more
- EPSS Score: %25.16
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4982
AVTECH AVN801 DVR has a security bypass via the administration login captcha... Read more
- EPSS Score: %4.00
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4976
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials... Read more
- EPSS Score: %9.35
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGH- EPSS Score: %14.07
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4968
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.33
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4891
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.... Read more
Affected Products : codeigniter- EPSS Score: %0.27
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-4868
Karotz API 12.07.19.00: Session Token Information Disclosure... Read more
Affected Products : api- EPSS Score: %22.15
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2013-4867
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking... Read more
- EPSS Score: %1.03
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.... Read more
- EPSS Score: %0.16
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.... Read more
- EPSS Score: %30.46
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2013-4863
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbit... Read more
- EPSS Score: %29.41
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024