2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4715 | — | — | 1.9% | Nov 6, 2013 | SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and ... |
| CVE-2013-4714 | — | — | 1.2% | Nov 6, 2013 | Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x befo... |
| CVE-2013-3906 | HIGH | 7.8 | 85.0% | Nov 6, 2013 | GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati... |
| CVE-2013-3626 | — | — | 2.8% | Nov 6, 2013 | Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 S... |
| CVE-2013-3286 | — | — | 0.9% | Nov 6, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to i... |
| CVE-2013-3281 | — | — | 1.0% | Nov 6, 2013 | Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07,... |
| CVE-2013-5689 | — | — | — | Nov 5, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5688. Reason: This issue has been MERGED with CV... |
| CVE-2013-5688 | — | — | 6.2% | Nov 5, 2013 | Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated use... |
| CVE-2013-4135 | — | — | 1.9% | Nov 5, 2013 | The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sen... |
| CVE-2013-4134 | — | — | 0.8% | Nov 5, 2013 | OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which m... |
| CVE-2013-6618 | — | — | 10.6% | Nov 5, 2013 | jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,... |
| CVE-2013-5695 | — | — | 1.0% | Nov 5, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary w... |
| CVE-2013-5694 | — | — | 2.6% | Nov 5, 2013 | SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arb... |
| CVE-2013-4497 | — | — | 1.8% | Nov 5, 2013 | The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply securit... |
| CVE-2013-4453 | — | — | 1.4% | Nov 5, 2013 | Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remot... |
| CVE-2013-4419 | — | — | 0.8% | Nov 5, 2013 | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not p... |
| CVE-2013-3264 | — | — | 2.1% | Nov 5, 2013 | The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) ... |
| CVE-2013-3263 | — | — | 1.6% | Nov 5, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier ... |
| CVE-2013-6617 | — | — | 3.0% | Nov 5, 2013 | The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it ea... |
| CVE-2013-6172 | — | — | 2.9% | Nov 5, 2013 | steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify con... |
| CVE-2013-6077 | — | — | 1.7% | Nov 5, 2013 | Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allow... |
| CVE-2013-5670 | — | — | 1.2% | Nov 5, 2013 | Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Se... |
| CVE-2013-4439 | — | — | 1.5% | Nov 5, 2013 | Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions v... |
| CVE-2013-4438 | — | — | 2.1% | Nov 5, 2013 | Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE... |
| CVE-2013-4437 | — | — | 1.5% | Nov 5, 2013 | Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "inse... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now