Latest CVE Feed
-
7.4
HIGHCVE-2013-2233
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.... Read more
Affected Products : ansible- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2013-2228
SaltStack RSA Key Generation allows remote users to decrypt communications... Read more
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-2213
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by ... Read more
Affected Products : paste_applet- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2198
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.... Read more
Affected Products : login_security- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGH- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2167
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass... Read more
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2166
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass... Read more
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2159
Monkey HTTP Daemon: broken user name authentication... Read more
Affected Products : monkey- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2013-2120
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.... Read more
Affected Products : paste_applet- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-2109
WordPress plugin wp-cleanfix has Remote Code Execution... Read more
Affected Products : wp_cleanfix- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2013-2103
OpenShift cartridge allows remote URL retrieval... Read more
Affected Products : openshift- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2013-2097
ZPanel through 10.1.0 has Remote Command Execution... Read more
Affected Products : zpanel- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2095
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection... Read more
Affected Products : openshift-origin-controller- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-2093
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.... Read more
Affected Products : dolibarr_erp\/crm- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-2092
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.... Read more
Affected Products : dolibarr_erp\/crm- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2091
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.... Read more
Affected Products : dolibarr_erp\/crm- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024