2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3725CRITICAL9.8Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
CVE-2013-7286HIGH7.5MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
CVE-2013-2637MEDIUM6.1A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 a...
CVE-2013-6681MEDIUM5.9Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability
CVE-2013-6236CRITICAL9.8IZON IP 2.0.2: hard-coded password vulnerability
CVE-2013-4395MEDIUM6.1Simple Machines Forum (SMF) through 2.0.5 has XSS
CVE-2013-4090HIGH7.5Varnish HTTP cache before 3.0.4: ACL bug
CVE-2013-3685HIGH7A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4...
CVE-2013-3494HIGH7.8A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loadin...
CVE-2013-2097HIGH7.8ZPanel through 10.1.0 has Remote Command Execution
CVE-2013-1938MEDIUM6.1Zimbra 2013 has XSS in aspell.php
CVE-2013-1924HIGH7.5Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2
CVE-2013-7381CRITICAL9.8libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a...
CVE-2013-2010CRITICAL9.8WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
CVE-2013-1410MEDIUM6.1Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
CVE-2013-7378CRITICAL9.8scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary c...
CVE-2013-4225HIGH8.8The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly ...
CVE-2013-2213MEDIUM5.5The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's...
CVE-2013-2120HIGH8.4The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not ...
CVE-2013-6499Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2013-5582HIGH7.8Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assiste...
CVE-2013-5988MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the...
CVE-2013-4448Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-5111. Reason: This candidate is a duplicate of C...
CVE-2013-3942HIGH7.8Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability
CVE-2013-3684CRITICAL9.8NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now