Search Results (40515 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-6364 2 Debian, Horde 2 Debian Linux, Groupware 2024-11-21 8.8 High
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
CVE-2013-6362 1 Xerox 24 Colorqube 9201, Colorqube 9201 Firmware, Colorqube 9202 and 21 more 2024-11-21 9.8 Critical
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
CVE-2013-6277 1 Qnap 2 Viocard 300, Viocard 300 Firmware 2024-11-21 7.5 High
QNAP VioCard 300 has hardcoded RSA private keys.
CVE-2013-6276 1 Qnap 10 Viocard-100, Viocard-100 Firmware, Viocard-30 and 7 more 2024-11-21 9.8 Critical
QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models
CVE-2013-6242 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name were SPLIT from this CVE ID because they affect different sets of versions.
CVE-2013-6239 1 Exis-ti 1 Exis Contexis 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter in a detail action.
CVE-2013-6236 1 Izoncam 2 Izon Ip, Izon Ip Firmware 2024-11-21 9.8 Critical
IZON IP 2.0.2: hard-coded password vulnerability
CVE-2013-6022 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
CVE-2013-5988 1 Semperplugins 1 All In One Seo Pack 2024-11-21 6.1 Medium
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.
CVE-2013-5978 1 Cart66 1 Cart66 Lite Plugin 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.
CVE-2013-5658 1 Aultware 1 Pwstore 2024-11-21 6.1 Medium
AultWare pwStore 2010.8.30.0 has XSS
CVE-2013-5638 1 Transcend-info 2 Wifisd, Wifisd Firmware 2024-11-21 5.4 Medium
Transcend WiFiSD 1.8 has persistent XSS
CVE-2013-5637 1 Pqigroup 2 Air Card, Air Card Firmware 2024-11-21 5.4 Medium
PQI AirCard has persistent XSS
CVE-2013-5212 1 Easyxdm 1 Easyxdm 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.
CVE-2013-4968 1 Puppet 1 Puppet Enterprise 2024-11-21 6.1 Medium
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
CVE-2013-4891 1 Codeigniter 1 Codeigniter 2024-11-21 N/A
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
CVE-2013-4791 1 Prestashop 1 Prestashop 2024-11-21 5.4 Medium
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
CVE-2013-4770 1 Eucalyptus 1 Eucalyptus Management Console 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-4752 2 Fedoraproject, Sensiolabs 2 Fedora, Symfony 2024-11-21 6.1 Medium
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.
CVE-2013-4718 1 Otrs 2 Otrs, Otrs Itsm 2024-11-21 5.4 Medium
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.