2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4303MEDIUM6.1includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21....
CVE-2013-3691HIGH7.5AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
CVE-2013-3542CRITICAL10Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3...
CVE-2013-4968MEDIUM6.1Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors relat...
CVE-2013-7371MEDIUM6.1node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete f...
CVE-2013-7370MEDIUM6.1node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
CVE-2013-6495MEDIUM6.1JBossWeb Bayeux has reflected XSS
CVE-2013-4593HIGH7.5RubyGem omniauth-facebook has an access token security vulnerability
CVE-2013-4245HIGH7.3Orca has arbitrary code execution due to insecure Python module load
CVE-2013-4158MEDIUM6.1smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
CVE-2013-1689MEDIUM6.5Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handli...
CVE-2013-4184MEDIUM5.5Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
CVE-2013-4133HIGH7.5kde-workspace before 4.10.5 has a memory leak in plasma desktop
CVE-2013-4120HIGH7.5Katello has a Denial of Service vulnerability in API OAuth authentication
CVE-2013-2183HIGH7.1Monkey HTTP Daemon has local security bypass
CVE-2013-2167CRITICAL9.8python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
CVE-2013-2166CRITICAL9.8python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
CVE-2013-2159CRITICAL9.8Monkey HTTP Daemon: broken user name authentication
CVE-2013-2095CRITICAL9.8rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perfor...
CVE-2013-1793HIGH7.5openstack-utils openstack-db has insecure password creation
CVE-2013-0293HIGH7.8oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
CVE-2013-0342MEDIUM4.3The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote atta...
CVE-2013-0326MEDIUM5.5OpenStack nova base images permissions are world readable
CVE-2013-0283MEDIUM5.4Katello: Username in Notification page has cross site scripting
CVE-2013-0243HIGH7.4haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TL...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now