2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4985 | HIGH | 7.5 | 9.0% | Dec 27, 2019 | Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream |
| CVE-2013-4982 | CRITICAL | 9.8 | 13.1% | Dec 27, 2019 | AVTECH AVN801 DVR has a security bypass via the administration login captcha |
| CVE-2013-4976 | CRITICAL | 9.8 | 36.1% | Dec 27, 2019 | Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials |
| CVE-2013-4975 | HIGH | 8.8 | 12.3% | Dec 27, 2019 | Hikvision DS-2CD7153-E IP Camera has Privilege Escalation |
| CVE-2013-4868 | MEDIUM | 5.3 | 5.0% | Dec 27, 2019 | Karotz API 12.07.19.00: Session Token Information Disclosure |
| CVE-2013-4867 | MEDIUM | 6.3 | 1.6% | Dec 27, 2019 | Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking |
| CVE-2013-4859 | HIGH | 8.1 | 7.0% | Dec 27, 2019 | INSTEON Hub 2242-222 lacks Web and API authentication |
| CVE-2013-4796 | HIGH | 8.8 | 1.9% | Dec 27, 2019 | ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request |
| CVE-2013-4764 | MEDIUM | 4.3 | 0.3% | Dec 27, 2019 | Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitr... |
| CVE-2013-4763 | MEDIUM | 4.6 | 0.4% | Dec 27, 2019 | Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission... |
| CVE-2013-4743 | CRITICAL | 9.8 | 8.4% | Dec 27, 2019 | Static HTTP Server 1.0 has a Local Overflow |
| CVE-2013-4692 | MEDIUM | 6.1 | 2.5% | Dec 27, 2019 | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS |
| CVE-2013-4621 | CRITICAL | 9.8 | 1.8% | Dec 27, 2019 | Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities |
| CVE-2013-4695 | HIGH | 7.8 | 5.3% | Dec 27, 2019 | Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution |
| CVE-2013-4693 | MEDIUM | 6.1 | 1.3% | Dec 27, 2019 | WordPress Xorbin Digital Flash Clock 1.0 has XSS |
| CVE-2013-4691 | MEDIUM | 6.1 | 0.6% | Dec 27, 2019 | Sencha Labs Connect has XSS with connect.methodOverride() |
| CVE-2013-4665 | MEDIUM | 6.5 | 1.3% | Dec 27, 2019 | SPBAS Business Automation Software 2012 has CSRF. |
| CVE-2013-4664 | MEDIUM | 6.1 | 2.2% | Dec 27, 2019 | SPBAS Business Automation Software 2012 has XSS. |
| CVE-2013-3088 | CRITICAL | 9.8 | 1.9% | Dec 26, 2019 | Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging". |
| CVE-2013-3085 | CRITICAL | 9.8 | 1.7% | Dec 26, 2019 | An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2. |
| CVE-2013-4318 | MEDIUM | 5.4 | 0.8% | Dec 26, 2019 | File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp dir... |
| CVE-2013-2011 | HIGH | 8.8 | 5.1% | Dec 26, 2019 | WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack... |
| CVE-2013-0202 | MEDIUM | 6.1 | 0.9% | Dec 17, 2019 | Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitr... |
| CVE-2013-5978 | MEDIUM | 6.1 | 4.1% | Dec 11, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr... |
| CVE-2013-5743 | CRITICAL | 9.8 | 80.0% | Dec 11, 2019 | Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now