2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-3049 | — | — | 1.1% | Oct 1, 2013 | IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass inte... |
| CVE-2013-3048 | — | — | 0.9% | Oct 1, 2013 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5... |
| CVE-2013-3047 | — | — | 1.2% | Oct 1, 2013 | IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privile... |
| CVE-2013-0451 | — | — | 1.0% | Oct 1, 2013 | SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote auth... |
| CVE-2013-5572 | — | — | 4.1% | Oct 1, 2013 | Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console acces... |
| CVE-2013-5370 | — | — | 4.2% | Oct 1, 2013 | Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote atta... |
| CVE-2013-4042 | — | — | 4.2% | Oct 1, 2013 | Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote atta... |
| CVE-2013-3278 | — | — | 0.3% | Oct 1, 2013 | EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local ... |
| CVE-2013-5725 | — | — | 1.1% | Oct 1, 2013 | The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows rem... |
| CVE-2013-5516 | — | — | 1.8% | Oct 1, 2013 | The Media Snapshot implementation on Cisco TelePresence Multipoint Switch (CTMS) devices allows remote authenticated use... |
| CVE-2013-3041 | — | — | 1.1% | Oct 1, 2013 | The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remot... |
| CVE-2013-5693 | — | — | 3.2% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web sc... |
| CVE-2013-5692 | — | — | 5.8% | Sep 30, 2013 | Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and... |
| CVE-2013-4623 | — | — | 1.9% | Sep 30, 2013 | The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certi... |
| CVE-2013-4362 | — | — | 1.2% | Sep 30, 2013 | WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1... |
| CVE-2013-4222 | — | — | 1.9% | Sep 30, 2013 | OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke ... |
| CVE-2013-2238 | — | — | 2.7% | Sep 30, 2013 | Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote a... |
| CVE-2013-1839 | — | — | 18.3% | Sep 30, 2013 | The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote atta... |
| CVE-2013-1444 | — | — | 0.3% | Sep 30, 2013 | A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwri... |
| CVE-2013-0211 | — | — | 3.9% | Sep 30, 2013 | Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 an... |
| CVE-2013-5963 | — | — | 4.2% | Sep 30, 2013 | Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows ... |
| CVE-2013-5962 | — | — | 14.8% | Sep 30, 2013 | Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r... |
| CVE-2013-5961 | — | — | 5.5% | Sep 30, 2013 | Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers... |
| CVE-2013-4378 | — | — | 2.8% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows rem... |
| CVE-2013-5697 | — | — | 1.3% | Sep 30, 2013 | SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote at... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now