2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2317 | — | — | 1.5% | Jun 3, 2013 | The Sleipnir Mobile application 2.9.1 and earlier and Sleipnir Mobile Black Edition application 2.9.1 and earlier for An... |
| CVE-2013-2316 | — | — | 1.5% | Jun 3, 2013 | The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vector... |
| CVE-2013-0464 | — | — | 1.8% | Jun 3, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SP... |
| CVE-2013-2950 | — | — | 1.4% | Jun 3, 2013 | CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x bef... |
| CVE-2013-0549 | — | — | 1.8% | Jun 3, 2013 | Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM We... |
| CVE-2013-3261 | — | — | 1.6% | Jun 1, 2013 | Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress ... |
| CVE-2013-2071 | — | — | 6.5% | Jun 1, 2013 | java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the thro... |
| CVE-2013-2067 | — | — | 7.1% | Jun 1, 2013 | java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21... |
| CVE-2013-0136 | — | — | 40.3% | Jun 1, 2013 | Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow... |
| CVE-2013-3735 | HIGH | 7.5 | 2.8% | May 31, 2013 | The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occur... |
| CVE-2013-3315 | — | — | 1.4% | May 31, 2013 | The server in TIBCO Silver Mobile 1.1.0 does not properly verify access to the administrator role before executing a com... |
| CVE-2013-1247 | — | — | 1.5% | May 31, 2013 | Cross-site scripting (XSS) vulnerability in the wireless configuration module in Cisco Prime Infrastructure allows remot... |
| CVE-2013-1246 | — | — | 1.7% | May 31, 2013 | Cisco TelePresence System Software does not properly handle inactive t-shell sessions, which allows remote authenticated... |
| CVE-2013-3721 | — | — | 2.3% | May 31, 2013 | SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL command... |
| CVE-2013-3720 | — | — | 1.6% | May 31, 2013 | Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remo... |
| CVE-2013-3719 | — | — | 1.4% | May 31, 2013 | Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attacker... |
| CVE-2013-3130 | — | — | — | May 30, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3660, CVE-2013-3661. Reason: This candidate is... |
| CVE-2013-2315 | — | — | 1.4% | May 29, 2013 | data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the in... |
| CVE-2013-2314 | — | — | 1.8% | May 29, 2013 | Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php i... |
| CVE-2013-2313 | — | — | 1.9% | May 29, 2013 | Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to hijack web session... |
| CVE-2013-2312 | — | — | 1.8% | May 29, 2013 | Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows ... |
| CVE-2013-1213 | — | — | 1.2% | May 29, 2013 | Cisco NX-OS on the Nexus 1000V does not assign the proper priority to heartbeat messages from a Virtual Ethernet Module ... |
| CVE-2013-1212 | — | — | 0.5% | May 29, 2013 | The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in... |
| CVE-2013-1211 | — | — | 1.1% | May 29, 2013 | Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supe... |
| CVE-2013-1210 | — | — | 1.1% | May 29, 2013 | Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now