Latest CVE Feed
-
5.3
MEDIUMCVE-2013-0570
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all... Read more
- EPSS Score: %0.18
- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2013-0522
The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmis... Read more
- EPSS Score: %0.04
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-0517
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.... Read more
Affected Products : sterling_external_authentication_server- EPSS Score: %0.12
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2013-0507
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.23
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0342
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.... Read more
Affected Products : pyrad- EPSS Score: %1.29
- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- EPSS Score: %0.11
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-0294
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.... Read more
- EPSS Score: %1.88
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-0293
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation... Read more
Affected Products : node- EPSS Score: %0.13
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-0291
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability... Read more
Affected Products : nextgen_gallery- EPSS Score: %32.11
- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.08
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.26
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-0267
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial ... Read more
- EPSS Score: %0.35
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-0264
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.... Read more
Affected Products : mrg_management_console- EPSS Score: %0.14
- Published: Dec. 30, 2019
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2013-0243
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections... Read more
Affected Products : hs-tls- EPSS Score: %0.37
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-0196
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting... Read more
- EPSS Score: %0.11
- Published: Dec. 30, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-0195
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.... Read more
Affected Products : matomo- EPSS Score: %0.47
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-0194
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.... Read more
Affected Products : matomo- EPSS Score: %0.47
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-0193
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.... Read more
Affected Products : matomo- EPSS Score: %0.47
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2013-0192
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.... Read more
Affected Products : simple_machines_forum- EPSS Score: %5.92
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-0186
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.40
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024