| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input. |
| On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to execute arbitrary code via TCP port 9000. |
| Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions. |
| Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions. |
| Zabbix before 5.0 represents passwords in the users table with unsalted MD5. |
| The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion. |
| The reflex-gallery plugin before 1.4.3 for WordPress has XSS. |
| The contact-form-plugin plugin before 3.3.5 for WordPress has XSS. |
| The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. |
| The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. |
| The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. |
| The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. |
| The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. |
| The contact-form-plugin plugin before 3.52 for WordPress has XSS. |
| Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users. |
| Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account. |
| The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter. |
| An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request. |
| cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310. |
| Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks. |