2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4303 | MEDIUM | 6.1 | 1.5% | Dec 11, 2019 | includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.... |
| CVE-2013-3691 | HIGH | 7.5 | 3.9% | Dec 11, 2019 | AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL. |
| CVE-2013-3542 | CRITICAL | 10 | 2.6% | Dec 11, 2019 | Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3... |
| CVE-2013-4968 | MEDIUM | 6.1 | 0.8% | Dec 11, 2019 | Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors relat... |
| CVE-2013-7371 | MEDIUM | 6.1 | 1.2% | Dec 11, 2019 | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete f... |
| CVE-2013-7370 | MEDIUM | 6.1 | 1.2% | Dec 11, 2019 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware |
| CVE-2013-6495 | MEDIUM | 6.1 | 0.6% | Dec 11, 2019 | JBossWeb Bayeux has reflected XSS |
| CVE-2013-4593 | HIGH | 7.5 | 1.8% | Dec 11, 2019 | RubyGem omniauth-facebook has an access token security vulnerability |
| CVE-2013-4245 | HIGH | 7.3 | 0.5% | Dec 11, 2019 | Orca has arbitrary code execution due to insecure Python module load |
| CVE-2013-4158 | MEDIUM | 6.1 | 1.2% | Dec 11, 2019 | smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) |
| CVE-2013-1689 | MEDIUM | 6.5 | 0.8% | Dec 10, 2019 | Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handli... |
| CVE-2013-4184 | MEDIUM | 5.5 | 0.5% | Dec 10, 2019 | Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks |
| CVE-2013-4133 | HIGH | 7.5 | 2.8% | Dec 10, 2019 | kde-workspace before 4.10.5 has a memory leak in plasma desktop |
| CVE-2013-4120 | HIGH | 7.5 | 1.3% | Dec 10, 2019 | Katello has a Denial of Service vulnerability in API OAuth authentication |
| CVE-2013-2183 | HIGH | 7.1 | 0.4% | Dec 10, 2019 | Monkey HTTP Daemon has local security bypass |
| CVE-2013-2167 | CRITICAL | 9.8 | 1.7% | Dec 10, 2019 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass |
| CVE-2013-2166 | CRITICAL | 9.8 | 1.8% | Dec 10, 2019 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
| CVE-2013-2159 | CRITICAL | 9.8 | 2.8% | Dec 10, 2019 | Monkey HTTP Daemon: broken user name authentication |
| CVE-2013-2095 | CRITICAL | 9.8 | 2.5% | Dec 10, 2019 | rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perfor... |
| CVE-2013-1793 | HIGH | 7.5 | 1.0% | Dec 10, 2019 | openstack-utils openstack-db has insecure password creation |
| CVE-2013-0293 | HIGH | 7.8 | 0.4% | Dec 10, 2019 | oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation |
| CVE-2013-0342 | MEDIUM | 4.3 | 1.5% | Dec 9, 2019 | The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote atta... |
| CVE-2013-0326 | MEDIUM | 5.5 | 0.4% | Dec 5, 2019 | OpenStack nova base images permissions are world readable |
| CVE-2013-0283 | MEDIUM | 5.4 | 0.6% | Dec 5, 2019 | Katello: Username in Notification page has cross site scripting |
| CVE-2013-0243 | HIGH | 7.4 | 1.0% | Dec 5, 2019 | haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TL... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now