|
288191
|
8.3 |
HIGH
Adjacent
|
silabs
|
zgm130s037hgn_firmware zm5202_firmware zm5101_firmware zgm2305a27hgn_firmware zgm230sb27hgn_firmware
|
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2013-20003
|
2024-11-21 10:50 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288192
|
9.8 |
CRITICAL
Network
|
themify
|
framework
|
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-20002
|
2024-11-21 10:50 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288193
|
7.5 |
HIGH
Network
|
openzfs
|
openzfs
|
An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is all…
|
NVD-CWE-noinfo
|
CVE-2013-20001
|
2024-11-21 10:50 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288194
|
7.5 |
HIGH
Network
|
python
|
python
|
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
|
NVD-CWE-noinfo
|
CVE-2013-1753
|
2024-11-21 10:50 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288195
|
9.8 |
CRITICAL
Network
|
berkeley
|
boinc
|
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-2018
|
2024-11-21 10:50 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288196
|
7.5 |
HIGH
Network
|
intel
|
82574l_controller_firmware
|
A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing…
|
CWE-665
Improper Initialization
|
CVE-2013-1634
|
2024-11-21 10:50 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288197
|
6.1 |
MEDIUM
Network
|
zimbra
|
zimbra
|
Zimbra 2013 has XSS in aspell.php
|
CWE-79
Cross-site Scripting
|
CVE-2013-1938
|
2024-11-21 10:50 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288198
|
7.5 |
HIGH
Network
|
skill
|
commerce_skrill
|
Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2
|
NVD-CWE-Other
|
CVE-2013-1924
|
2024-11-21 10:50 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288199
|
9.8 |
CRITICAL
Network
|
boldgrid automattic
|
w3_total_cache wp_super_cache
|
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
|
CWE-74
Injection
|
CVE-2013-2010
|
2024-11-21 10:50 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288200
|
9.8 |
CRITICAL
Network
|
yabb
|
yabb
|
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-2057
|
2024-11-21 10:50 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|