Latest CVE Feed
-
5.4
MEDIUMCVE-2013-4718
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.... Read more
- EPSS Score: %0.19
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4717
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Ke... Read more
- EPSS Score: %0.76
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4695
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution... Read more
Affected Products : winamp- EPSS Score: %3.50
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4693
WordPress Xorbin Digital Flash Clock 1.0 has XSS... Read more
Affected Products : digital_flash_clock- EPSS Score: %0.26
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4692
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS... Read more
Affected Products : analog_flash_clock- EPSS Score: %4.01
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4691
Sencha Labs Connect has XSS with connect.methodOverride()... Read more
Affected Products : connect- EPSS Score: %0.33
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-4665
SPBAS Business Automation Software 2012 has CSRF.... Read more
Affected Products : business_automation_software- EPSS Score: %0.30
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4664
SPBAS Business Automation Software 2012 has XSS.... Read more
Affected Products : business_automation_software- EPSS Score: %3.59
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-4658
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.... Read more
- EPSS Score: %0.61
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-4657
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.... Read more
- EPSS Score: %0.52
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-4656
Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.... Read more
- EPSS Score: %0.74
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4655
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.... Read more
- EPSS Score: %0.64
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGH- EPSS Score: %0.91
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4621
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities... Read more
Affected Products : magnolia_cms- EPSS Score: %0.12
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2013-4602
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.... Read more
- EPSS Score: %0.26
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4593
RubyGem omniauth-facebook has an access token security vulnerability... Read more
Affected Products : omniauth-facebook- EPSS Score: %0.35
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-4584
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections... Read more
- EPSS Score: %0.58
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4583
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositori... Read more
- EPSS Score: %0.29
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-4582
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote aut... Read more
- EPSS Score: %0.16
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4572
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.... Read more
- EPSS Score: %1.02
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024