Latest CVE Feed
-
6.5
MEDIUMCVE-2013-4861
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.... Read more
- EPSS Score: %14.56
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGH- EPSS Score: %8.60
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %1.32
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUM- EPSS Score: %0.23
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4855
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.... Read more
- EPSS Score: %0.30
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGH- EPSS Score: %0.23
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4796
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request... Read more
Affected Products : reviewboard- EPSS Score: %0.63
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4792
PrestaShop before 1.4.11 allows logout CSRF.... Read more
Affected Products : prestashop- EPSS Score: %0.10
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-4791
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.... Read more
Affected Products : prestashop- EPSS Score: %0.21
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4770
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : eucalyptus_management_console- EPSS Score: %0.22
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4764
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.... Read more
- EPSS Score: %0.16
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2013-4763
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.... Read more
- EPSS Score: %0.18
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4752
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attack... Read more
- EPSS Score: %0.93
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGH- EPSS Score: %0.60
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4743
Static HTTP Server 1.0 has a Local Overflow... Read more
Affected Products : static_http_server- EPSS Score: %8.05
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-4718
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.... Read more
- EPSS Score: %0.19
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4717
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Ke... Read more
- EPSS Score: %0.76
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4695
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution... Read more
Affected Products : winamp- EPSS Score: %3.50
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4693
WordPress Xorbin Digital Flash Clock 1.0 has XSS... Read more
Affected Products : digital_flash_clock- EPSS Score: %0.26
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4692
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS... Read more
Affected Products : analog_flash_clock- EPSS Score: %4.01
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024