Latest CVE Feed
-
7.3
HIGHCVE-2013-2012
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.... Read more
- EPSS Score: %0.10
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-2011
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.... Read more
Affected Products : w3_super_cache- EPSS Score: %5.91
- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2010
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability... Read more
- EPSS Score: %83.16
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-2009
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution... Read more
Affected Products : wp_super_cache- EPSS Score: %26.01
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-2008
WordPress Super Cache Plugin 1.3 has XSS.... Read more
Affected Products : wp_super_cache- EPSS Score: %0.26
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-20004
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. Th... Read more
Affected Products : iscsi_san- EPSS Score: %0.47
- Published: Feb. 06, 2022
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2013-20003
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.... Read more
- EPSS Score: %0.14
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-20002
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.... Read more
Affected Products : framework- EPSS Score: %2.80
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-20001
An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configurati... Read more
Affected Products : openzfs- EPSS Score: %0.17
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-1951
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.... Read more
- EPSS Score: %1.78
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2013-1945
ruby193 uses an insecure LD_LIBRARY_PATH setting.... Read more
Affected Products : ruby193- EPSS Score: %0.11
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %2.28
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-1934
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.... Read more
- EPSS Score: %0.35
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-1932
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.... Read more
Affected Products : mantisbt- EPSS Score: %0.69
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-1931
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.... Read more
- EPSS Score: %1.43
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1930
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.... Read more
- EPSS Score: %0.70
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1924
Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2... Read more
Affected Products : commerce_skrill- EPSS Score: %0.24
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-1916
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.... Read more
Affected Products : user_photo- EPSS Score: %26.48
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1910
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.... Read more
- EPSS Score: %0.85
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1895
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.... Read more
- EPSS Score: %0.28
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024