Vulnerabilities (CVE)

Total 395116 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-3646 1 Cybozu 1 Cybozu Live 2026-06-16 6.8 MEDIUM N/A
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.
CVE-2013-3645 1 Orchardproject 1 Orchard 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-3644 1 Justsystems 4 Ichitaro, Ichitaro Just School, Ichitaro Portable and 1 more 2026-06-16 10.0 HIGH N/A
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document.
CVE-2013-3643 1 Adgjm 1 Galapagos Browser 2026-06-16 4.3 MEDIUM N/A
The Galapagos Browser application for Android does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.
CVE-2013-3642 2 Adgjm, Google 2 Angel Browser, Android 2026-06-16 4.3 MEDIUM N/A
The Angel Browser application 1.47b and earlier for Android 1.6 through 2.1, 1.62b and earlier for Android 2.2 through 2.3.4, 1.68b and earlier for Android 3.0 through 4.0.3, and 1.76b and earlier for Android 4.1 through 4.2 does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.
CVE-2013-3641 1 Pizzahut 1 Pizza Hut Japan Official Order Application 2026-06-16 5.8 MEDIUM N/A
The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2013-3640 1 Filemaker 2 Filemaker Pro, Filemaker Pro Advanced 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-3639 1 Xaraya 1 Xaraya 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) interface, (3) name, or (4) tabmodule parameter to index.php.
CVE-2013-3638 1 Boonex 1 Dolphin 2026-06-16 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.
CVE-2013-3637 1 Projectpier 1 Projectpier 2026-06-16 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 does not use the Secure flag for cookies
CVE-2013-3636 1 Projectpier 1 Projectpier 2026-06-16 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
CVE-2013-3635 1 Projectpier 1 Projectpier 2026-06-16 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 has stored XSS
CVE-2013-3634 1 Siemens 7 Scalance X200-4p Irt, Scalance X200irt Firmware, Scalance X201-3p Irt and 4 more 2026-06-16 7.5 HIGH N/A
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The implementation of SNMPv3 does not check the user credentials sufficiently. Therefore, an attacker is able to execute SNMP commands without correct credentials.
CVE-2013-3633 1 Siemens 7 Scalance X200-4p Irt, Scalance X200irt Firmware, Scalance X201-3p Irt and 4 more 2026-06-16 8.0 HIGH N/A
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.1.0). The user privileges for the web interface are only enforced on client side and not properly verified on server side. Therefore, an attacker is able to execute privileged commands using an unprivileged account.
CVE-2013-3632 1 Openmediavault 1 Openmediavault 2026-06-16 9.0 HIGH 8.8 HIGH
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
CVE-2013-3631 1 Nas4free 1 Nas4free 2026-06-16 6.0 MEDIUM N/A
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy.
CVE-2013-3630 1 Moodle 1 Moodle 2026-06-16 4.6 MEDIUM N/A
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
CVE-2013-3629 1 Ispconfig 1 Ispconfig 2026-06-16 6.5 MEDIUM 8.8 HIGH
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
CVE-2013-3628 1 Zabbix 1 Zabbix 2026-06-16 6.5 MEDIUM 8.8 HIGH
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
CVE-2013-3627 1 Mcafee 1 Agent 2026-06-16 5.0 MEDIUM N/A
FrameworkService.exe in McAfee Framework Service in McAfee Managed Agent (MA) before 4.5.0.1927 and 4.6 before 4.6.0.3258 allows remote attackers to cause a denial of service (service crash) via a malformed HTTP request.