Latest CVE Feed
-
4.3
MEDIUMCVE-2013-1930
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.... Read more
- EPSS Score: %0.70
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1924
Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2... Read more
Affected Products : commerce_skrill- EPSS Score: %0.24
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-1916
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.... Read more
Affected Products : user_photo- EPSS Score: %26.48
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1910
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.... Read more
- EPSS Score: %0.85
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1895
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.... Read more
- EPSS Score: %0.28
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-1891
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.... Read more
- EPSS Score: %4.02
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1889
mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI script to break out of the chroot.... Read more
Affected Products : mod_ruid2- EPSS Score: %0.59
- Published: Nov. 08, 2019
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2013-1867
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability... Read more
- EPSS Score: %0.15
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2013-1866
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability... Read more
- EPSS Score: %0.15
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-1820
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.... Read more
- EPSS Score: %0.14
- Published: Nov. 08, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1817
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.... Read more
- EPSS Score: %1.40
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1816
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.... Read more
- EPSS Score: %3.48
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1811
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".... Read more
- EPSS Score: %0.32
- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1809
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.... Read more
- EPSS Score: %1.70
- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %0.28
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1771
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.... Read more
Affected Products : monkey- EPSS Score: %0.39
- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-1760
The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities... Read more
Affected Products : the_bug_genie- EPSS Score: %0.35
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-1753
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.... Read more
Affected Products : python- EPSS Score: %0.42
- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-1751
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.... Read more
Affected Products : twiki- EPSS Score: %4.69
- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1744
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.... Read more
Affected Products : iris_citations_management_tool- EPSS Score: %19.52
- Published: Jan. 25, 2020
- Modified: Nov. 21, 2024