2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-3093 | HIGH | 8.8 | 0.7% | Jan 28, 2020 | ASUS RT-N56U devices allow CSRF. |
| CVE-2013-3074 | HIGH | 7.5 | 1.7% | Jan 28, 2020 | NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device... |
| CVE-2013-3071 | CRITICAL | 9.8 | 2.1% | Jan 28, 2020 | NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. |
| CVE-2013-1601 | MEDIUM | 5.3 | 12.7% | Jan 28, 2020 | An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processin... |
| CVE-2013-1600 | MEDIUM | 5.3 | 18.5% | Jan 28, 2020 | An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0... |
| CVE-2013-2764 | MEDIUM | 6.1 | 0.9% | Jan 28, 2020 | Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct ... |
| CVE-2013-2748 | CRITICAL | 9.8 | 13.1% | Jan 28, 2020 | Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. |
| CVE-2013-2714 | MEDIUM | 6.1 | 2.7% | Jan 28, 2020 | Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web s... |
| CVE-2013-1599 | CRITICAL | 9.8 | 40.4% | Jan 28, 2020 | A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm... |
| CVE-2013-4865 | MEDIUM | 6.5 | 1.7% | Jan 28, 2020 | Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows... |
| CVE-2013-4864 | CRITICAL | 9.8 | 6.3% | Jan 28, 2020 | MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url... |
| CVE-2013-4863 | HIGH | 8.8 | 12.2% | Jan 28, 2020 | The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a... |
| CVE-2013-4862 | HIGH | 8.1 | 3.7% | Jan 28, 2020 | MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to... |
| CVE-2013-4861 | MEDIUM | 6.5 | 6.6% | Jan 28, 2020 | Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote... |
| CVE-2013-4583 | HIGH | 8.8 | 2.0% | Jan 28, 2020 | The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise... |
| CVE-2013-4582 | MEDIUM | 6.5 | 1.9% | Jan 28, 2020 | The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in G... |
| CVE-2013-2060 | CRITICAL | 9.8 | 5.5% | Jan 28, 2020 | The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metac... |
| CVE-2013-0294 | MEDIUM | 5.9 | 2.8% | Jan 28, 2020 | packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes... |
| CVE-2013-6455 | MEDIUM | 5.3 | 1.1% | Jan 28, 2020 | The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attac... |
| CVE-2013-6451 | MEDIUM | 6.1 | 1.1% | Jan 28, 2020 | Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.... |
| CVE-2013-2571 | CRITICAL | 9.8 | 16.2% | Jan 28, 2020 | Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary ... |
| CVE-2013-1895 | HIGH | 7.5 | 2.8% | Jan 28, 2020 | The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to ... |
| CVE-2013-1437 | CRITICAL | 9.8 | 2.9% | Jan 28, 2020 | Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute a... |
| CVE-2013-2612 | CRITICAL | 9.8 | 3.0% | Jan 27, 2020 | Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary ... |
| CVE-2013-2499 | HIGH | 7.5 | 3.3% | Jan 27, 2020 | SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via sp... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now