2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2013-10006HIGH7.5A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is...
CVE-2013-10005HIGH7.5The RemoteAddr and LocalAddr methods on the returned net.Conn may call themselves, leading to an infinite loop which wil...
CVE-2013-4253HIGH7.5The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a de...
CVE-2013-1916HIGH8.8In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl...
CVE-2013-20003HIGH8.3Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key...
CVE-2013-4717HIGH8.8Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before ...
CVE-2013-4536HIGH7.8An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to c...
CVE-2013-20001HIGH7.5An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs featu...
CVE-2013-7488HIGH7.5perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop...
CVE-2013-1753HIGH7.5The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denia...
CVE-2013-4227HIGH8.8Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Pers...
CVE-2013-3722HIGH7.5A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
CVE-2013-5687HIGH7.5RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
CVE-2013-6360HIGH7.5TRENDnet TS-S402 has a backdoor to enable TELNET.
CVE-2013-6277HIGH7.5QNAP VioCard 300 has hardcoded RSA private keys.
CVE-2013-1634HIGH7.5A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller d...
CVE-2013-5106HIGH8.8A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
CVE-2013-7286HIGH7.5MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
CVE-2013-4090HIGH7.5Varnish HTTP cache before 3.0.4: ACL bug
CVE-2013-3685HIGH7A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4...
CVE-2013-3494HIGH7.8A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loadin...
CVE-2013-2097HIGH7.8ZPanel through 10.1.0 has Remote Command Execution
CVE-2013-1924HIGH7.5Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2
CVE-2013-4225HIGH8.8The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly ...
CVE-2013-2120HIGH8.4The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now