2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4227HIGH8.8Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Pers...
CVE-2013-4454CRITICAL9.1WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
CVE-2013-5594MEDIUM4.3Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
CVE-2013-7324MEDIUM5.3Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpe...
CVE-2013-3722HIGH7.5A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
CVE-2013-3738CRITICAL9.8A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, ...
CVE-2013-4211CRITICAL9.8A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, wh...
CVE-2013-5687HIGH7.5RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
CVE-2013-5212MEDIUM6.1Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via t...
CVE-2013-4792MEDIUM5.5PrestaShop before 1.4.11 allows logout CSRF.
CVE-2013-4791MEDIUM5.4PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XS...
CVE-2013-7287CRITICAL9.8MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
CVE-2013-7173CRITICAL9.8Belkin n750 routers have a buffer overflow.
CVE-2013-7098CRITICAL9.8OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.
CVE-2013-6927MEDIUM5.5Internet TRiLOGI Server (unknown versions) could allow a local user to bypass security and create a local user account.
CVE-2013-6362CRITICAL9.8Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
CVE-2013-6360HIGH7.5TRENDnet TS-S402 has a backdoor to enable TELNET.
CVE-2013-6277HIGH7.5QNAP VioCard 300 has hardcoded RSA private keys.
CVE-2013-1634HIGH7.5A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller d...
CVE-2013-1401CRITICAL9.8Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPre...
CVE-2013-1400CRITICAL9.8Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to exec...
CVE-2013-0295Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0342. Reason: This candidate is a duplicate of [...
CVE-2013-6022MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, whic...
CVE-2013-5106HIGH8.8A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
CVE-2013-4602MEDIUM5.5A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified fun...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now