2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-1647 | — | — | 1.8% | Sep 5, 2013 | Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 befo... |
| CVE-2013-1646 | — | — | 1.4% | Sep 5, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and... |
| CVE-2013-1645 | — | — | 2.9% | Sep 5, 2013 | Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev... |
| CVE-2013-5471 | — | — | 1.0% | Sep 5, 2013 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Global Site Selector (GSS) allows remote a... |
| CVE-2013-3479 | — | — | 1.2% | Sep 5, 2013 | Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attacke... |
| CVE-2013-5470 | — | — | 1.9% | Sep 4, 2013 | Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows... |
| CVE-2013-3469 | — | — | 1.8% | Sep 4, 2013 | Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain ... |
| CVE-2013-1661 | — | — | 1.1% | Sep 4, 2013 | VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, whic... |
| CVE-2013-5664 | — | — | 2.3% | Aug 31, 2013 | Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS bef... |
| CVE-2013-5663 | — | — | 2.8% | Aug 31, 2013 | The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows ... |
| CVE-2013-4702 | — | — | 2.1% | Aug 30, 2013 | Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKO... |
| CVE-2013-3485 | — | — | 0.4% | Aug 30, 2013 | Multiple untrusted search path vulnerabilities in Soda PDF 5.1.183.10520 allow local users to gain privileges via a Troj... |
| CVE-2013-5469 | — | — | 2.4% | Aug 30, 2013 | The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED... |
| CVE-2013-3474 | — | — | 1.2% | Aug 30, 2013 | The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to caus... |
| CVE-2013-3470 | — | — | 3.0% | Aug 30, 2013 | The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted versi... |
| CVE-2013-3467 | — | — | 0.3% | Aug 30, 2013 | Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain si... |
| CVE-2013-3463 | — | — | 2.4% | Aug 30, 2013 | The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle... |
| CVE-2013-5648 | — | — | 2.1% | Aug 29, 2013 | Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, a... |
| CVE-2013-5647 | — | — | 2.0% | Aug 29, 2013 | lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell m... |
| CVE-2013-5646 | — | — | 1.2% | Aug 29, 2013 | Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitr... |
| CVE-2013-5645 | — | — | 1.9% | Aug 29, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attacke... |
| CVE-2013-5589 | — | — | 2.0% | Aug 29, 2013 | SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary S... |
| CVE-2013-5588 | — | — | 1.2% | Aug 29, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitra... |
| CVE-2013-5209 | — | — | 2.5% | Aug 29, 2013 | The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3... |
| CVE-2013-4003 | — | — | 0.9% | Aug 29, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now