2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3591HIGH8.8vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
CVE-2013-4334CRITICAL9.8opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
CVE-2013-2009HIGH8.8WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
CVE-2013-2008MEDIUM6.1WordPress Super Cache Plugin 1.3 has XSS.
CVE-2013-1202HIGH7.5Cisco ACE A2(3.6) allows log retention DoS.
CVE-2013-0192MEDIUM4.9File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
CVE-2013-3638HIGH8.8SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL co...
CVE-2013-3568HIGH8.8Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentica...
CVE-2013-3564MEDIUM5.3The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view ...
CVE-2013-2684MEDIUM6.1Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web...
CVE-2013-2683MEDIUM5.3Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers...
CVE-2013-4521CRITICAL9.8RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for wh...
CVE-2013-4572HIGH7.5The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-C...
CVE-2013-4166HIGH7.5The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data ...
CVE-2013-2682MEDIUM4.3Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain ...
CVE-2013-2681CRITICAL9.8Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to...
CVE-2013-2680HIGH7.5Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive in...
CVE-2013-5989——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4969. Reason: This candidate is a duplicate of C...
CVE-2013-2675MEDIUM6.5Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could a...
CVE-2013-0507HIGH8.1IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
CVE-2013-2678HIGH8.1Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers...
CVE-2013-2676HIGH7.5Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attacker...
CVE-2013-7055CRITICAL9.8D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
CVE-2013-7054MEDIUM6.1D-Link DIR-100 4.03B07: cli.cgi XSS
CVE-2013-7053HIGH8.8D-Link DIR-100 4.03B07: cli.cgi CSRF

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now