|
287051
|
6.1 |
MEDIUM
Network
|
united-security-providers
|
secure_entry_server
|
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
|
CWE-601
Open Redirect
|
CVE-2013-2764
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287052
|
9.8 |
CRITICAL
Network
|
belkin
|
wemo_switch_firmware
|
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-2748
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287053
|
6.1 |
MEDIUM
Network
|
podpress_project
|
podpress
|
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2714
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287054
|
9.8 |
CRITICAL
Network
|
huawei
|
e587_firmware
|
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.
|
CWE-78
OS Command
|
CVE-2013-2612
|
2024-11-21 10:52 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287055
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
|
CWE-426
Untrusted Search Path
|
CVE-2013-2773
|
2024-11-21 10:52 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287056
|
9.8 |
CRITICAL
Network
|
belkin
|
n900_firmware
|
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
|
CWE-287
Improper Authentication
|
CVE-2013-3088
|
2024-11-21 10:52 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287057
|
9.8 |
CRITICAL
Network
|
belkin
|
f5d8236-4_firmware
|
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
|
CWE-287
Improper Authentication
|
CVE-2013-3085
|
2024-11-21 10:52 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287058
|
9.8 |
CRITICAL
Network
|
minidlna_project debian
|
minidlna debian_linux
|
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
|
CWE-89
SQL Injection
|
CVE-2013-2745
|
2024-11-21 10:52 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287059
|
6.5 |
MEDIUM
Network
|
otrs debian opensuse
|
otrs_help_desk otrs_itsm faq debian_linux opensuse
|
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking…
|
CWE-269
Improper Privilege Management
|
CVE-2013-2625
|
2024-11-21 10:52 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287060
|
9.8 |
CRITICAL
Network
|
netgear
|
wndr4700_firmware
|
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, cau…
|
CWE-287
Improper Authentication
|
CVE-2013-3072
|
2024-11-21 10:52 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|