2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4373 | — | — | 0.3% | Oct 24, 2013 | The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load a... |
| CVE-2013-4295 | — | — | 12.2% | Oct 24, 2013 | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML d... |
| CVE-2013-4293 | — | — | 0.3% | Oct 24, 2013 | The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obta... |
| CVE-2013-2236 | — | — | 2.1% | Oct 24, 2013 | Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.9... |
| CVE-2013-6245 | — | — | 4.7% | Oct 24, 2013 | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3... |
| CVE-2013-6244 | — | — | 1.6% | Oct 24, 2013 | The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier... |
| CVE-2013-3244 | — | — | 1.7% | Oct 24, 2013 | Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for ... |
| CVE-2013-6243 | — | — | 2.5% | Oct 23, 2013 | SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote ... |
| CVE-2013-4422 | — | — | 2.1% | Oct 23, 2013 | SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, al... |
| CVE-2013-2651 | — | — | 2.1% | Oct 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitra... |
| CVE-2013-5703 | — | — | 1.3% | Oct 22, 2013 | The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or... |
| CVE-2013-5389 | — | — | 0.9% | Oct 22, 2013 | Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote a... |
| CVE-2013-5388 | — | — | 0.9% | Oct 22, 2013 | Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote a... |
| CVE-2013-1739 | — | — | 3.4% | Oct 22, 2013 | Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read o... |
| CVE-2013-5550 | — | — | 0.3% | Oct 22, 2013 | The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to cause a denial of servic... |
| CVE-2013-5544 | — | — | 1.7% | Oct 22, 2013 | The VPN authentication functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to caus... |
| CVE-2013-5446 | — | — | 1.7% | Oct 22, 2013 | The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which h... |
| CVE-2013-5428 | — | — | 1.7% | Oct 22, 2013 | IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows... |
| CVE-2013-4382 | — | — | — | Oct 21, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5937. Reason: This candidate is a duplicate of... |
| CVE-2013-4381 | — | — | — | Oct 21, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5938. Reason: This candidate is a duplicate of... |
| CVE-2013-4450 | — | — | 37.2% | Oct 21, 2013 | The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of se... |
| CVE-2013-5971 | — | — | 2.0% | Oct 21, 2013 | Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remo... |
| CVE-2013-5970 | — | — | 1.5% | Oct 21, 2013 | hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (... |
| CVE-2013-5542 | — | — | 1.9% | Oct 21, 2013 | Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.2), 8.7 before 8.7(1.8), 9.0 before 9.0(3.6), and 9.1 ... |
| CVE-2013-6129 | — | — | 51.9% | Oct 19, 2013 | The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now