2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3212HIGH8.1vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote atta...
CVE-2013-3093HIGH8.8ASUS RT-N56U devices allow CSRF.
CVE-2013-3074HIGH7.5NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device...
CVE-2013-3071CRITICAL9.8NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
CVE-2013-1601MEDIUM5.3An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processin...
CVE-2013-1600MEDIUM5.3An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0...
CVE-2013-2764MEDIUM6.1Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct ...
CVE-2013-2748CRITICAL9.8Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
CVE-2013-2714MEDIUM6.1Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web s...
CVE-2013-1599CRITICAL9.8A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm...
CVE-2013-4865MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows...
CVE-2013-4864CRITICAL9.8MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url...
CVE-2013-4863HIGH8.8The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a...
CVE-2013-4862HIGH8.1MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to...
CVE-2013-4861MEDIUM6.5Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote...
CVE-2013-4583HIGH8.8The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise...
CVE-2013-4582MEDIUM6.5The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in G...
CVE-2013-2060CRITICAL9.8The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metac...
CVE-2013-0294MEDIUM5.9packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes...
CVE-2013-6455MEDIUM5.3The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attac...
CVE-2013-6451MEDIUM6.1Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22....
CVE-2013-2571CRITICAL9.8Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary ...
CVE-2013-1895HIGH7.5The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to ...
CVE-2013-1437CRITICAL9.8Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute a...
CVE-2013-2612CRITICAL9.8Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now