2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-2679MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow rem...
CVE-2013-4227HIGH8.8Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Pers...
CVE-2013-4454CRITICAL9.1WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
CVE-2013-5594MEDIUM4.3Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
CVE-2013-7324MEDIUM5.3Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpe...
CVE-2013-3722HIGH7.5A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
CVE-2013-3738CRITICAL9.8A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, ...
CVE-2013-4211CRITICAL9.8A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, wh...
CVE-2013-5687HIGH7.5RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
CVE-2013-5212MEDIUM6.1Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via t...
CVE-2013-4792MEDIUM5.5PrestaShop before 1.4.11 allows logout CSRF.
CVE-2013-4791MEDIUM5.4PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XS...
CVE-2013-7287CRITICAL9.8MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
CVE-2013-7173CRITICAL9.8Belkin n750 routers have a buffer overflow.
CVE-2013-7098CRITICAL9.8OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.
CVE-2013-6927MEDIUM5.5Internet TRiLOGI Server (unknown versions) could allow a local user to bypass security and create a local user account.
CVE-2013-6362CRITICAL9.8Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
CVE-2013-6360HIGH7.5TRENDnet TS-S402 has a backdoor to enable TELNET.
CVE-2013-6277HIGH7.5QNAP VioCard 300 has hardcoded RSA private keys.
CVE-2013-1634HIGH7.5A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller d...
CVE-2013-1401CRITICAL9.8Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPre...
CVE-2013-1400CRITICAL9.8Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to exec...
CVE-2013-0295——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0342. Reason: This candidate is a duplicate of [...
CVE-2013-6022MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, whic...
CVE-2013-5106HIGH8.8A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now