|
290041
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.
|
CWE-352
Origin Validation Error
|
CVE-2013-1639
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290042
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
|
CWE-94
Code Injection
|
CVE-2013-1638
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290043
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
|
CWE-94
Code Injection
|
CVE-2013-1637
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290044
|
9.8 |
CRITICAL
Network
|
cardozatechnologies
|
wordpress_poll
|
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and del…
|
CWE-89
SQL Injection
|
CVE-2013-1401
|
2024-11-21 10:49 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290045
|
9.8 |
CRITICAL
Network
|
cardozatechnologies
|
wordpress_poll
|
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollRes…
|
CWE-89
SQL Injection
|
CVE-2013-1400
|
2024-11-21 10:49 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290046
|
6.1 |
MEDIUM
Network
|
perforce
|
p4web
|
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
|
CWE-79
Cross-site Scripting
|
CVE-2013-1410
|
2024-11-21 10:49 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290047
|
9.8 |
CRITICAL
Network
|
pdfkit_project
|
pdfkit
|
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability
|
CWE-20
Improper Input Validation
|
CVE-2013-1607
|
2024-11-21 10:49 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290048
|
9.8 |
CRITICAL
Network
|
sonicwall
|
analyzer global_management_system viewpoint universal_management_appliance
|
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and Vi…
|
CWE-287
Improper Authentication
|
CVE-2013-1359
|
2024-11-21 10:49 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290049
|
9.8 |
CRITICAL
Network
|
sonicwall
|
analyzer global_management_system viewpoint universal_management_appliance
|
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and Vi…
|
CWE-287
Improper Authentication
|
CVE-2013-1360
|
2024-11-21 10:49 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290050
|
5.4 |
MEDIUM
Network
|
orangehrm
|
orangehrm
|
Orange HRM 2.7.1 allows XSS via the vacancy name.
|
CWE-79
Cross-site Scripting
|
CVE-2013-1353
|
2024-11-21 10:49 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|