2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4334CRITICAL9.8opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
CVE-2013-2009HIGH8.8WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
CVE-2013-2008MEDIUM6.1WordPress Super Cache Plugin 1.3 has XSS.
CVE-2013-1202HIGH7.5Cisco ACE A2(3.6) allows log retention DoS.
CVE-2013-0192MEDIUM4.9File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
CVE-2013-3638HIGH8.8SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL co...
CVE-2013-3568HIGH8.8Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentica...
CVE-2013-3564MEDIUM5.3The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view ...
CVE-2013-2684MEDIUM6.1Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web...
CVE-2013-2683MEDIUM5.3Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers...
CVE-2013-4521CRITICAL9.8RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for wh...
CVE-2013-4572HIGH7.5The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-C...
CVE-2013-4166HIGH7.5The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data ...
CVE-2013-2682MEDIUM4.3Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain ...
CVE-2013-2681CRITICAL9.8Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to...
CVE-2013-2680HIGH7.5Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive in...
CVE-2013-5989Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4969. Reason: This candidate is a duplicate of C...
CVE-2013-2675MEDIUM6.5Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could a...
CVE-2013-0507HIGH8.1IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
CVE-2013-2678HIGH8.1Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers...
CVE-2013-2676HIGH7.5Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attacker...
CVE-2013-7055CRITICAL9.8D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
CVE-2013-7054MEDIUM6.1D-Link DIR-100 4.03B07: cli.cgi XSS
CVE-2013-7053HIGH8.8D-Link DIR-100 4.03B07: cli.cgi CSRF
CVE-2013-7052CRITICAL9.8D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now