2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4782 | — | — | 26.0% | Jul 8, 2013 | The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands b... |
| CVE-2013-3273 | — | — | 0.3% | Jul 8, 2013 | EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the clearte... |
| CVE-2013-3272 | — | — | 0.3% | Jul 8, 2013 | EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for l... |
| CVE-2013-2205 | — | — | 3.0% | Jul 8, 2013 | The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, whic... |
| CVE-2013-2204 | — | — | 2.9% | Jul 8, 2013 | moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other product... |
| CVE-2013-2203 | — | — | 2.0% | Jul 8, 2013 | WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive inf... |
| CVE-2013-2202 | — | — | 2.3% | Jul 8, 2013 | WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an... |
| CVE-2013-2201 | — | — | 2.1% | Jul 8, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary... |
| CVE-2013-2200 | — | — | 1.8% | Jul 8, 2013 | WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to byp... |
| CVE-2013-2199 | — | — | 2.0% | Jul 8, 2013 | The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified... |
| CVE-2013-0237 | — | — | 3.1% | Jul 8, 2013 | Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before ... |
| CVE-2013-0236 | — | — | 2.5% | Jul 8, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary... |
| CVE-2013-0235 | — | — | 28.9% | Jul 8, 2013 | The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct ... |
| CVE-2013-1615 | — | — | 0.8% | Jul 8, 2013 | The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x ... |
| CVE-2013-1614 | — | — | 1.5% | Jul 8, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Securit... |
| CVE-2013-1613 | — | — | 1.5% | Jul 8, 2013 | SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (S... |
| CVE-2013-1414 | — | — | 2.3% | Jul 8, 2013 | Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.... |
| CVE-2013-1059 | — | — | 4.5% | Jul 8, 2013 | net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer... |
| CVE-2013-3299 | — | — | 2.2% | Jul 6, 2013 | RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption... |
| CVE-2013-3005 | — | — | 3.0% | Jul 6, 2013 | The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated ... |
| CVE-2013-2341 | — | — | 3.1% | Jul 6, 2013 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658... |
| CVE-2013-2340 | — | — | 10.7% | Jul 6, 2013 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658... |
| CVE-2013-0581 | — | — | 0.9% | Jul 6, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 be... |
| CVE-2013-2237 | — | — | 0.6% | Jul 4, 2013 | The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain st... |
| CVE-2013-2234 | — | — | 0.6% | Jul 4, 2013 | The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.1... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now