2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-1648——The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does ...
CVE-2013-1647——Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 befo...
CVE-2013-1646——Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and...
CVE-2013-1645——Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev...
CVE-2013-5471——Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Global Site Selector (GSS) allows remote a...
CVE-2013-3479——Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attacke...
CVE-2013-5470——Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows...
CVE-2013-3469——Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain ...
CVE-2013-1661——VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, whic...
CVE-2013-5664——Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS bef...
CVE-2013-5663——The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows ...
CVE-2013-4702——Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKO...
CVE-2013-3485——Multiple untrusted search path vulnerabilities in Soda PDF 5.1.183.10520 allow local users to gain privileges via a Troj...
CVE-2013-5469——The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED...
CVE-2013-3474——The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to caus...
CVE-2013-3470——The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted versi...
CVE-2013-3467——Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain si...
CVE-2013-3463——The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle...
CVE-2013-5648——Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, a...
CVE-2013-5647——lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell m...
CVE-2013-5646——Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitr...
CVE-2013-5645——Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attacke...
CVE-2013-5589——SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary S...
CVE-2013-5588——Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitra...
CVE-2013-5209——The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now