2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4985HIGH7.5Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
CVE-2013-4982CRITICAL9.8AVTECH AVN801 DVR has a security bypass via the administration login captcha
CVE-2013-4976CRITICAL9.8Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
CVE-2013-4975HIGH8.8Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
CVE-2013-4868MEDIUM5.3Karotz API 12.07.19.00: Session Token Information Disclosure
CVE-2013-4867MEDIUM6.3Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
CVE-2013-4859HIGH8.1INSTEON Hub 2242-222 lacks Web and API authentication
CVE-2013-4796HIGH8.8ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
CVE-2013-4764MEDIUM4.3Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitr...
CVE-2013-4763MEDIUM4.6Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission...
CVE-2013-4743CRITICAL9.8Static HTTP Server 1.0 has a Local Overflow
CVE-2013-4692MEDIUM6.1Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
CVE-2013-4621CRITICAL9.8Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
CVE-2013-4695HIGH7.8Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
CVE-2013-4693MEDIUM6.1WordPress Xorbin Digital Flash Clock 1.0 has XSS
CVE-2013-4691MEDIUM6.1Sencha Labs Connect has XSS with connect.methodOverride()
CVE-2013-4665MEDIUM6.5SPBAS Business Automation Software 2012 has CSRF.
CVE-2013-4664MEDIUM6.1SPBAS Business Automation Software 2012 has XSS.
CVE-2013-3088CRITICAL9.8Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
CVE-2013-3085CRITICAL9.8An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
CVE-2013-4318MEDIUM5.4File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp dir...
CVE-2013-2011HIGH8.8WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack...
CVE-2013-0202MEDIUM6.1Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitr...
CVE-2013-5978MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr...
CVE-2013-5743CRITICAL9.8Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now