2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7051HIGH8.8D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
CVE-2013-1422MEDIUM5.3webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
CVE-2013-2674HIGH7.5Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attacker...
CVE-2013-2673MEDIUM6.8Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate at...
CVE-2013-2672HIGH7.5Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
CVE-2013-2646HIGH7.5TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
CVE-2013-2631MEDIUM5.3TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to ob...
CVE-2013-2624MEDIUM5.3Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive...
CVE-2013-2623MEDIUM6.1Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the...
CVE-2013-2622MEDIUM6.1Cross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML...
CVE-2013-2621MEDIUM6.1Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victim...
CVE-2013-3565MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allo...
CVE-2013-3489HIGH7.8Buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0 allows remote attackers to execute arbitrary...
CVE-2013-3488HIGH7.8Stack-based buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0.7858 allows remote attackers to ...
CVE-2013-5116HIGH7.1Evernote prior to 5.5.1 has insecure password change
CVE-2013-5114MEDIUM6.1LastPass prior to 2.5.1 allows secure wipe bypass.
CVE-2013-5113MEDIUM6.8LastPass prior to 2.5.1 has an insecure PIN implementation.
CVE-2013-5112MEDIUM4.6Evernote before 5.5.1 has insecure PIN storage
CVE-2013-3322HIGH7.2NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot ...
CVE-2013-4241MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow rem...
CVE-2013-4187MEDIUM6.5The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote auth...
CVE-2013-2294MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi...
CVE-2013-2198CRITICAL9.8The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intend...
CVE-2013-1867MEDIUM6.1Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
CVE-2013-1866MEDIUM6.1OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now