Search Results (322822 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-5116 1 Evernote 1 Evernote 2024-11-21 7.1 High
Evernote prior to 5.5.1 has insecure password change
CVE-2013-5114 1 Logmein 1 Lastpass 2024-11-21 6.1 Medium
LastPass prior to 2.5.1 allows secure wipe bypass.
CVE-2013-5113 1 Logmein 1 Lastpass 2024-11-21 6.8 Medium
LastPass prior to 2.5.1 has an insecure PIN implementation.
CVE-2013-5112 1 Evernote 1 Evernote 2024-11-21 4.6 Medium
Evernote before 5.5.1 has insecure PIN storage
CVE-2013-5106 1 Python-mode Project 1 Python-mode 2024-11-21 8.8 High
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
CVE-2013-5027 1 O-dyn 1 Collabtive 2024-11-21 9.8 Critical
Collabtive 1.0 has incorrect access control
CVE-2013-4985 1 Vivotek 6 Ip7160, Ip7160 Firmware, Ip7361 and 3 more 2024-11-21 7.5 High
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
CVE-2013-4982 1 Avtech 2 Avn801 Dvr, Avn801 Dvr Firmware 2024-11-21 9.8 Critical
AVTECH AVN801 DVR has a security bypass via the administration login captcha
CVE-2013-4976 1 Hikvision 2 Ds-2cd7153-e, Ds-2cd7153-e Firmware 2024-11-21 9.8 Critical
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
CVE-2013-4975 1 Hikvision 2 Ds-2cd7153-e, Ds-2cd7153-e Firmware 2024-11-21 8.8 High
Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
CVE-2013-4968 1 Puppet 1 Puppet Enterprise 2024-11-21 6.1 Medium
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
CVE-2013-4891 1 Codeigniter 1 Codeigniter 2024-11-21 N/A
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
CVE-2013-4868 1 Karotz 1 Api 2024-11-21 5.3 Medium
Karotz API 12.07.19.00: Session Token Information Disclosure
CVE-2013-4867 1 Ea 2 Karotz Smart Rabbit, Karotz Smart Rabbit Firmware 2024-11-21 6.3 Medium
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
CVE-2013-4865 1 Micasaverde 2 Veralite, Veralite Firmware 2024-11-21 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
CVE-2013-4864 1 Micasaverde 2 Veralite, Veralite Firmware 2024-11-21 9.8 Critical
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
CVE-2013-4863 1 Micasaverde 2 Veralite, Veralite Firmware 2024-11-21 8.8 High
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to port_49451/upnp/control/hag.
CVE-2013-4862 1 Micasaverde 2 Veralite, Veralite Firmware 2024-11-21 8.1 High
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.
CVE-2013-4861 1 Micasaverde 2 Veralite, Veralite Firmware 2024-11-21 6.5 Medium
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.
CVE-2013-4859 1 Insteon 2 Hub, Hub Firmware 2024-11-21 8.1 High
INSTEON Hub 2242-222 lacks Web and API authentication