2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4965 | — | — | 1.3% | Oct 25, 2013 | Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, wh... |
| CVE-2013-4957 | — | — | 1.1% | Oct 25, 2013 | The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted rep... |
| CVE-2013-4465 | — | — | 2.4% | Oct 25, 2013 | Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 ... |
| CVE-2013-4434 | — | — | 5.7% | Oct 25, 2013 | Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depend... |
| CVE-2013-4421 | — | — | 6.4% | Oct 25, 2013 | The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial ... |
| CVE-2013-1067 | — | — | 0.4% | Oct 25, 2013 | Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users... |
| CVE-2013-6128 | — | — | 2.6% | Oct 25, 2013 | The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 doe... |
| CVE-2013-6127 | — | — | 13.9% | Oct 25, 2013 | The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 ... |
| CVE-2013-5424 | — | — | 1.3% | Oct 25, 2013 | IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user ... |
| CVE-2013-3989 | — | — | 0.8% | Oct 25, 2013 | IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which a... |
| CVE-2013-6281 | — | — | 5.2% | Oct 25, 2013 | Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 f... |
| CVE-2013-6280 | — | — | 1.6% | Oct 25, 2013 | Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac... |
| CVE-2013-5549 | — | — | 1.7% | Oct 25, 2013 | Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B rout... |
| CVE-2013-5531 | — | — | 1.3% | Oct 25, 2013 | Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support... |
| CVE-2013-5530 | — | — | 2.3% | Oct 25, 2013 | The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.... |
| CVE-2013-5522 | — | — | 0.3% | Oct 25, 2013 | Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to ga... |
| CVE-2013-5521 | — | — | 1.2% | Oct 25, 2013 | Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers ... |
| CVE-2013-3280 | — | — | 2.3% | Oct 25, 2013 | EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which ... |
| CVE-2013-5537 | — | — | 1.3% | Oct 24, 2013 | The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management... |
| CVE-2013-5536 | — | — | 1.5% | Oct 24, 2013 | Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remo... |
| CVE-2013-5148 | — | — | 0.3% | Oct 24, 2013 | Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock ... |
| CVE-2013-5143 | — | — | 0.6% | Oct 24, 2013 | The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified cir... |
| CVE-2013-5130 | — | — | 0.9% | Oct 24, 2013 | WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes ... |
| CVE-2013-4443 | — | — | — | Oct 24, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2013-4299 | — | — | 3.8% | Oct 24, 2013 | Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticate... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now