2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4555 | — | — | 1.2% | Nov 18, 2013 | Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attacker... |
| CVE-2013-4551 | — | — | 0.8% | Nov 18, 2013 | Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNC... |
| CVE-2013-4510 | — | — | 2.1% | Nov 18, 2013 | Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remo... |
| CVE-2013-4480 | — | — | 2.1% | Nov 18, 2013 | Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satelli... |
| CVE-2013-4425 | — | — | 0.4% | Nov 18, 2013 | The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "Su... |
| CVE-2013-4204 | — | — | 1.1% | Nov 18, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) be... |
| CVE-2013-2114 | — | — | 2.3% | Nov 18, 2013 | Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6... |
| CVE-2013-2061 | — | — | 2.8% | Nov 18, 2013 | The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers... |
| CVE-2013-2032 | — | — | 2.5% | Nov 18, 2013 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using bot... |
| CVE-2013-2031 | — | — | 2.5% | Nov 18, 2013 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, ... |
| CVE-2013-1057 | — | — | 0.6% | Nov 18, 2013 | Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrar... |
| CVE-2013-6794 | — | — | 1.4% | Nov 14, 2013 | Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers t... |
| CVE-2013-6793 | — | — | 3.2% | Nov 14, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote a... |
| CVE-2013-6226 | — | — | 2.2% | Nov 14, 2013 | Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXp... |
| CVE-2013-6168 | — | — | 1.2% | Nov 14, 2013 | Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject ... |
| CVE-2013-6164 | — | — | 3.4% | Nov 14, 2013 | SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar... |
| CVE-2013-6163 | — | — | 1.7% | Nov 14, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in ProjeQtOr (formerly Project'Or RIA) before 4.0.0 allow remote att... |
| CVE-2013-6058 | — | — | 2.5% | Nov 14, 2013 | SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2013-6780 | — | — | 2.4% | Nov 13, 2013 | Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 all... |
| CVE-2013-6685 | — | — | 0.3% | Nov 13, 2013 | The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allow... |
| CVE-2013-6684 | — | — | 0.9% | Nov 13, 2013 | The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, wh... |
| CVE-2013-6683 | — | — | 0.7% | Nov 13, 2013 | The IPv6 implementation in Cisco NX-OS does not properly handle neighbor-table adjacencies, which allows remote attacker... |
| CVE-2013-6682 | — | — | 0.7% | Nov 13, 2013 | The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly... |
| CVE-2013-6628 | — | — | 1.0% | Nov 13, 2013 | net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that ... |
| CVE-2013-6627 | — | — | 5.3% | Nov 13, 2013 | net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now