Latest CVE Feed
-
4.3
MEDIUMCVE-2013-4228
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read ... Read more
Affected Products : organic_groups- EPSS Score: %0.23
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4227
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security t... Read more
Affected Products : persona- EPSS Score: %0.20
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-4226
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via t... Read more
Affected Products : authenticated_user_page_caching- EPSS Score: %0.24
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4225
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "c... Read more
Affected Products : restful_web_services- EPSS Score: %0.55
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4211
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code... Read more
Affected Products : openx- EPSS Score: %88.60
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2013-4209
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.... Read more
Affected Products : automatic_bug_reporting_tool- EPSS Score: %0.04
- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4201
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.... Read more
- EPSS Score: %0.12
- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-4187
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.... Read more
Affected Products : flippy- EPSS Score: %0.68
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4184
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks... Read more
- EPSS Score: %0.04
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4176
mysecureshell 1.31: Local Information Disclosure Vulnerability... Read more
Affected Products : mysecureshell- EPSS Score: %0.06
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4175
MySecureShell 1.31 has a Local Denial of Service Vulnerability... Read more
Affected Products : mysecureshell- EPSS Score: %0.12
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4170
In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into such a string without being sanitized. This means that if ... Read more
Affected Products : ember.js- EPSS Score: %0.32
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4168
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.... Read more
- EPSS Score: %0.58
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4166
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted ... Read more
- EPSS Score: %1.00
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4161
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.... Read more
- EPSS Score: %0.05
- Published: Dec. 31, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.63
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4144
There is an object injection vulnerability in swfupload plugin for wordpress.... Read more
Affected Products : swfupload- EPSS Score: %0.45
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGH- EPSS Score: %1.99
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4120
Katello has a Denial of Service vulnerability in API OAuth authentication... Read more
- EPSS Score: %0.55
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-4110
Cryptocat has an Unspecified Chat Participant User List Disclosure... Read more
Affected Products : cryptocat- EPSS Score: %0.55
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024