Latest CVE Feed
-
9.3
HIGHCVE-2013-2516
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.... Read more
Affected Products : fileutils- EPSS Score: %2.38
- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2513
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.... Read more
Affected Products : flash_tool- EPSS Score: %0.59
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-2512
The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.... Read more
Affected Products : ftpd- EPSS Score: %2.84
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-2499
SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.... Read more
Affected Products : simplehrm- EPSS Score: %1.16
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-2474
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.... Read more
Affected Products : aws_xms- EPSS Score: %34.23
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-2294
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in... Read more
Affected Products : viewgit- EPSS Score: %4.74
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2013-2267
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.... Read more
Affected Products : fudforum- EPSS Score: %12.80
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-2262
Cryptocat strophe.js before 2.0.22 has information disclosure... Read more
Affected Products : cryptocat- EPSS Score: %0.47
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-2261
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure... Read more
Affected Products : cryptocat- EPSS Score: %7.85
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2260
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness... Read more
Affected Products : cryptocat- EPSS Score: %0.50
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2259
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview... Read more
Affected Products : cryptocat- EPSS Score: %0.72
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-2258
Cryptocat before 2.0.22 has Nickname User Impersonation... Read more
Affected Products : cryptocat- EPSS Score: %0.42
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-2257
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness... Read more
Affected Products : cryptocat- EPSS Score: %0.42
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-2255
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.... Read more
- EPSS Score: %0.41
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2013-2233
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.... Read more
Affected Products : ansible- EPSS Score: %0.37
- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2013-2228
SaltStack RSA Key Generation allows remote users to decrypt communications... Read more
- EPSS Score: %1.02
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %31.19
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-2213
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by ... Read more
Affected Products : paste_applet- EPSS Score: %0.06
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2198
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.... Read more
Affected Products : login_security- EPSS Score: %0.53
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGH- EPSS Score: %0.05
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024