|
285751
|
6.1 |
MEDIUM
Network
|
telaen_project
|
telaen
|
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
|
CWE-601
Open Redirect
|
CVE-2013-2621
|
2024-11-21 10:52 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285752
|
8.8 |
HIGH
Network
|
asus
|
rt-n56u_firmware rt-n10u_firmware dsl-n55u_firmware rt-ac66u_firmware rt-n15u_firmware rt-n53_firmware rt-n16_firmware
|
ASUS RT-N56U devices allow CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2013-3093
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285753
|
7.5 |
HIGH
Network
|
netgear
|
wndr4700_firmware
|
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-3074
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285754
|
9.8 |
CRITICAL
Network
|
netgear
|
wndr4700_firmware
|
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
|
CWE-287
Improper Authentication
|
CVE-2013-3071
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285755
|
6.1 |
MEDIUM
Network
|
united-security-providers
|
secure_entry_server
|
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
|
CWE-601
Open Redirect
|
CVE-2013-2764
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285756
|
9.8 |
CRITICAL
Network
|
belkin
|
wemo_switch_firmware
|
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-2748
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285757
|
6.1 |
MEDIUM
Network
|
podpress_project
|
podpress
|
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2714
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285758
|
9.8 |
CRITICAL
Network
|
huawei
|
e587_firmware
|
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.
|
CWE-78
OS Command
|
CVE-2013-2612
|
2024-11-21 10:52 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285759
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
|
CWE-426
Untrusted Search Path
|
CVE-2013-2773
|
2024-11-21 10:52 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285760
|
9.8 |
CRITICAL
Network
|
belkin
|
n900_firmware
|
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
|
CWE-287
Improper Authentication
|
CVE-2013-3088
|
2024-11-21 10:52 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|