2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5314 | — | — | 1.6% | Aug 19, 2013 | Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows... |
| CVE-2013-5313 | — | — | 0.9% | Aug 19, 2013 | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlie... |
| CVE-2013-5312 | — | — | 3.2% | Aug 19, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit... |
| CVE-2013-5311 | — | — | 2.3% | Aug 19, 2013 | Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL com... |
| CVE-2013-4881 | — | — | 2.2% | Aug 19, 2013 | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlie... |
| CVE-2013-2175 | — | — | 3.5% | Aug 19, 2013 | HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a nega... |
| CVE-2013-2162 | — | — | 0.4% | Aug 19, 2013 | Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and... |
| CVE-2013-4808 | — | — | 4.4% | Aug 18, 2013 | Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31 and Service Center 6.2.8 allows remote attack... |
| CVE-2013-4248 | — | — | 3.6% | Aug 18, 2013 | The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not ... |
| CVE-2013-4238 | — | — | 5.3% | Aug 18, 2013 | The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in... |
| CVE-2013-4073 | — | — | 2.8% | Aug 18, 2013 | The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.... |
| CVE-2013-2022 | — | — | 2.7% | Aug 17, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) ... |
| CVE-2013-1888 | — | — | 0.4% | Aug 17, 2013 | pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temp... |
| CVE-2013-5310 | — | — | 1.4% | Aug 16, 2013 | SQL injection vulnerability in the DB Integration (wfqbe) extension before 2.0.1 for TYPO3 allows remote attackers to ex... |
| CVE-2013-5309 | — | — | 1.2% | Aug 16, 2013 | Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, ... |
| CVE-2013-5308 | — | — | 1.2% | Aug 16, 2013 | Cross-site scripting (XSS) vulnerability in the RealURL Management (realurlmanagement) extension 0.3.4 and earlier for T... |
| CVE-2013-5307 | — | — | 1.3% | Aug 16, 2013 | Cross-site scripting (XSS) vulnerability in the Faceted Search (ke_search) extension before 1.4.1 for TYPO3 allows remot... |
| CVE-2013-5306 | — | — | 1.2% | Aug 16, 2013 | SQL injection vulnerability in the Browser - TYPO3 without PHP (browser) extension before 4.5.5 for TYPO3 allows remote ... |
| CVE-2013-5305 | — | — | 1.3% | Aug 16, 2013 | Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote a... |
| CVE-2013-5304 | — | — | 1.4% | Aug 16, 2013 | SQL injection vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to e... |
| CVE-2013-5303 | — | — | 1.9% | Aug 16, 2013 | Unspecified vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 has unknown impact and remote ... |
| CVE-2013-5302 | — | — | 1.4% | Aug 16, 2013 | SQL injection vulnerability in the Faceted Search (ke_search) extension before 1.4.1 for TYPO3 allows remote attackers t... |
| CVE-2013-5301 | — | — | 3.4% | Aug 16, 2013 | Directory traversal vulnerability in help.php in Trustport Webfilter 5.5.0.2232 allows remote attackers to read arbitrar... |
| CVE-2013-4114 | — | — | 2.4% | Aug 16, 2013 | The automatic update request in Nagstamont before 0.9.10 uses a cleartext base64 format for transmission of a username a... |
| CVE-2013-3319 | — | — | 20.9% | Aug 16, 2013 | The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitiv... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now