Total
394770 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2013-2262 | 1 Cryptocat Project | 1 Cryptocat | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Cryptocat strophe.js before 2.0.22 has information disclosure | |||||
| CVE-2013-2261 | 1 Cryptocat Project | 1 Cryptocat | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | |||||
| CVE-2013-2260 | 1 Cryptocat Project | 1 Cryptocat | 2026-06-16 | 5.0 MEDIUM | 9.8 CRITICAL |
| Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | |||||
| CVE-2013-2259 | 1 Cryptocat Project | 1 Cryptocat | 2026-06-16 | 7.5 HIGH | 9.8 CRITICAL |
| Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | |||||
| CVE-2013-2258 | 1 Cryptocat Project | 1 Cryptocat | 2026-06-16 | 5.0 MEDIUM | 5.3 MEDIUM |
| Cryptocat before 2.0.22 has Nickname User Impersonation | |||||
| CVE-2013-2257 | 1 Cryptocat Project | 1 Cryptocat | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness | |||||
| CVE-2013-2256 | 1 Openstack | 1 Nova | 2026-06-16 | 6.0 MEDIUM | N/A |
| OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id. | |||||
| CVE-2013-2255 | 3 Debian, Openstack, Redhat | 4 Debian Linux, Compute, Keystone and 1 more | 2026-06-16 | 4.3 MEDIUM | 5.9 MEDIUM |
| HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. | |||||
| CVE-2013-2254 | 1 Apache | 2 Org.apache.sling.servlets.post, Sling | 2026-06-16 | 5.0 MEDIUM | N/A |
| The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors. | |||||
| CVE-2013-2251 | 5 Apache, Fujitsu, Microsoft and 2 more | 9 Archiva, Struts, Interstage Business Process Manager Analytics and 6 more | 2026-06-16 | 9.3 HIGH | 9.8 CRITICAL |
| Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix. | |||||
| CVE-2013-2250 | 1 Apache | 1 Ofbiz | 2026-06-16 | 10.0 HIGH | N/A |
| Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions. | |||||
| CVE-2013-2249 | 1 Apache | 1 Http Server | 2026-06-16 | 7.5 HIGH | N/A |
| mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors. | |||||
| CVE-2013-2248 | 1 Apache | 1 Struts | 2026-06-16 | 5.8 MEDIUM | N/A |
| Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix. | |||||
| CVE-2013-2247 | 2 Drupal, Fast Permissions Administration Project | 2 Drupal, Fast Permission Administration | 2026-06-16 | 7.5 HIGH | N/A |
| The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit form. | |||||
| CVE-2013-2246 | 1 Moodle | 1 Moodle | 2026-06-16 | 4.0 MEDIUM | N/A |
| mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time. | |||||
| CVE-2013-2245 | 1 Moodle | 1 Moodle | 2026-06-16 | 4.0 MEDIUM | N/A |
| rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed. | |||||
| CVE-2013-2244 | 1 Moodle | 1 Moodle | 2026-06-16 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field. | |||||
| CVE-2013-2243 | 1 Moodle | 1 Moodle | 2026-06-16 | 4.0 MEDIUM | N/A |
| mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document. | |||||
| CVE-2013-2242 | 1 Moodle | 1 Moodle | 2026-06-16 | 4.0 MEDIUM | N/A |
| mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server. | |||||
| CVE-2013-2241 | 1 Menalto | 1 Gallery | 2026-06-16 | 5.0 MEDIUM | N/A |
| modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter. | |||||
