|
285991
|
9.1 |
CRITICAL
Network
|
getbutterfly
|
portable-phpmyadmin
|
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
|
CWE-287
Improper Authentication
|
CVE-2013-4454
|
2024-11-21 10:55 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285992
|
9.8 |
CRITICAL
Network
|
openx
|
openx
|
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code
|
CWE-94
Code Injection
|
CVE-2013-4211
|
2024-11-21 10:55 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285993
|
5.5 |
MEDIUM
Local
|
avira
|
antivir_mailgate antivir_mailgate_suite exchange_security antivir_webgate antivir_webgate_suite antivir_sharepoint professional_security antivir_personal savapi antivirus_s…
|
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-4602
|
2024-11-21 10:55 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285994
|
6.1 |
MEDIUM
Network
|
simplemachines
|
simple_machines_forum
|
Simple Machines Forum (SMF) through 2.0.5 has XSS
|
CWE-79
Cross-site Scripting
|
CVE-2013-4395
|
2024-11-21 10:55 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285995
|
8.8 |
HIGH
Network
|
restful_web_services_project
|
restful_web_services
|
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote au…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2013-4225
|
2024-11-21 10:55 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285996
|
8.8 |
HIGH
Local
|
qemu redhat
|
qemu enterprise_linux_server_tus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation virtualization
|
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
|
CWE-20
Improper Input Validation
|
CVE-2013-4535
|
2024-11-21 10:55 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285997
|
9.8 |
CRITICAL
Network
|
pydio
|
pydio
|
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSC…
|
CWE-78
OS Command
|
CVE-2013-4267
|
2024-11-21 10:55 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285998
|
9.8 |
CRITICAL
Network
|
openpne
|
opopensocialplugin
|
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
|
CWE-776
XML Entity Expansion
|
CVE-2013-4335
|
2024-11-21 10:55 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285999
|
9.8 |
CRITICAL
Network
|
tejimaya
|
opwebapiplugin
|
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
|
CWE-611
XXE
|
CVE-2013-4334
|
2024-11-21 10:55 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286000
|
9.8 |
CRITICAL
Network
|
nuxeo
|
nuxeo
|
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to exe…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2013-4521
|
2024-11-21 10:55 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|