Latest CVE Feed
-
6.1
MEDIUMCVE-2013-7482
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.... Read more
Affected Products : reflex_gallery- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7481
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.... Read more
Affected Products : contact_form- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7480
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.... Read more
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7479
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.... Read more
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7478
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.... Read more
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7477
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.... Read more
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-7476
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.... Read more
Affected Products : simple_fields- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7475
The contact-form-plugin plugin before 3.52 for WordPress has XSS.... Read more
Affected Products : contact_form- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7474
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.... Read more
Affected Products : windu_cms- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-7473
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.... Read more
Affected Products : windu_cms- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7472
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.... Read more
Affected Products : count_per_day- Published: Jun. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-7471
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, ... Read more
Affected Products : dir-645_firmware dir-300_firmware dir-600_firmware dir-845_firmware dir-865_firmware dir-600 dir-300 dir-645 dir-845 dir-865- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2013-7470
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013... Read more
Affected Products : linux_kernel- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-7469
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.... Read more
Affected Products : seafile- Published: Feb. 21, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2013-7468
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.... Read more
Affected Products : simple_machines_forum- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-7467
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.... Read more
Affected Products : simple_machines_forum- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-7466
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.... Read more
Affected Products : simple_machines_forum- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-7465
Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary code by uploading PHP scripts.... Read more
Affected Products : servers_ultimate- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-7464
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.... Read more
Affected Products : csrf-magic- Published: Aug. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-7435
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.... Read more
Affected Products : evergreen- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024