2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4784The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbit...
CVE-2013-4783The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allo...
CVE-2013-4782The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands b...
CVE-2013-3273EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the clearte...
CVE-2013-3272EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for l...
CVE-2013-2205The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, whic...
CVE-2013-2204moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other product...
CVE-2013-2203WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive inf...
CVE-2013-2202WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an...
CVE-2013-2201Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary...
CVE-2013-2200WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to byp...
CVE-2013-2199The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified...
CVE-2013-0237Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before ...
CVE-2013-0236Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary...
CVE-2013-0235The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct ...
CVE-2013-1615The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x ...
CVE-2013-1614Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Securit...
CVE-2013-1613SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (S...
CVE-2013-1414Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3....
CVE-2013-1059net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer...
CVE-2013-3299RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption...
CVE-2013-3005The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated ...
CVE-2013-2341Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658...
CVE-2013-2340Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658...
CVE-2013-0581Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 be...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now