2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3093HIGH8.8ASUS RT-N56U devices allow CSRF.
CVE-2013-3074HIGH7.5NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device...
CVE-2013-3071CRITICAL9.8NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
CVE-2013-1601MEDIUM5.3An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processin...
CVE-2013-1600MEDIUM5.3An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0...
CVE-2013-2764MEDIUM6.1Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct ...
CVE-2013-2748CRITICAL9.8Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
CVE-2013-2714MEDIUM6.1Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web s...
CVE-2013-1599CRITICAL9.8A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm...
CVE-2013-4865MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows...
CVE-2013-4864CRITICAL9.8MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url...
CVE-2013-4863HIGH8.8The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a...
CVE-2013-4862HIGH8.1MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to...
CVE-2013-4861MEDIUM6.5Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote...
CVE-2013-4583HIGH8.8The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise...
CVE-2013-4582MEDIUM6.5The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in G...
CVE-2013-2060CRITICAL9.8The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metac...
CVE-2013-0294MEDIUM5.9packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes...
CVE-2013-6455MEDIUM5.3The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attac...
CVE-2013-6451MEDIUM6.1Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22....
CVE-2013-2571CRITICAL9.8Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary ...
CVE-2013-1895HIGH7.5The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to ...
CVE-2013-1437CRITICAL9.8Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute a...
CVE-2013-2612CRITICAL9.8Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary ...
CVE-2013-2499HIGH7.5SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via sp...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now