| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195. |
| File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config. |
| Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. |
| Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds. |
| Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm. |
| cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. |
| OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS |
| Havalite CMS 1.1.7 has a stored XSS vulnerability |
| The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg. |
| Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4. |
| Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*. |
| The sharebar plugin before 1.2.2 for WordPress has SQL injection. |
| The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491. |
| The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562. |
| The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. |
| The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header. |
| The count-per-day plugin before 3.2.3 for WordPress has XSS via search words. |
| The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues. |
| In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption. |