|
284811
|
- |
|
project-redcap vanderbilt
|
redcap
|
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4609
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284812
|
- |
|
project-redcap vanderbilt
|
redcap
|
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4608
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284813
|
9.8 |
CRITICAL
Network
|
swfupload_project
|
swfupload
|
There is an object injection vulnerability in swfupload plugin for wordpress.
|
CWE-74
Injection
|
CVE-2013-4144
|
2024-11-21 10:54 |
2022-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284814
|
6.5 |
MEDIUM
Network
|
otrs
|
otrs
|
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote atta…
|
CWE-200
Information Exposure
|
CVE-2013-4088
|
2024-11-21 10:54 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284815
|
7.5 |
HIGH
Network
|
opensips
|
opensips
|
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2013-3722
|
2024-11-21 10:54 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284816
|
9.8 |
CRITICAL
Network
|
zabbix
|
zabbix
|
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2013-3738
|
2024-11-21 10:54 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284817
|
9.8 |
CRITICAL
Network
|
invisioncommunity
|
invision_power_board
|
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
|
NVD-CWE-noinfo
|
CVE-2013-3725
|
2024-11-21 10:54 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284818
|
7.5 |
HIGH
Network
|
varnish_cache_project
|
varnish_cache
|
Varnish HTTP cache before 3.0.4: ACL bug
|
NVD-CWE-Other
|
CVE-2013-4090
|
2024-11-21 10:54 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284819
|
7.0 |
HIGH
Local
|
spritesoftware
|
spritebackup spritebud
|
A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, …
|
CWE-362
Race Condition
|
CVE-2013-3685
|
2024-11-21 10:54 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284820
|
7.8 |
HIGH
Local
|
daum
|
potplayer
|
Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability
|
CWE-426
Untrusted Search Path
|
CVE-2013-3942
|
2024-11-21 10:54 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|