2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-0163MEDIUM5.5OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
CVE-2013-2745CRITICAL9.8An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
CVE-2013-7325HIGH8.8An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code vi...
CVE-2013-4486CRITICAL9.8Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
CVE-2013-4411MEDIUM4.3Review Board: URL processing gives unauthorized users access to review lists
CVE-2013-4235MEDIUM4.7shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
CVE-2013-2228HIGH8.1SaltStack RSA Key Generation allows remote users to decrypt communications
CVE-2013-2106HIGH7.5webauth before 4.6.1 has authentication credential disclosure
CVE-2013-2103HIGH8.1OpenShift cartridge allows remote URL retrieval
CVE-2013-2101MEDIUM5.4Katello has multiple XSS issues in various entities
CVE-2013-4410HIGH7.5ReviewBoard: has an access-control problem in REST API
CVE-2013-7484HIGH7.5Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
CVE-2013-2625MEDIUM6.5An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0...
CVE-2013-4224Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4187. Reason: This candidate is a duplicate of C...
CVE-2013-6879MEDIUM5.3The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information ...
CVE-2013-6878MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remot...
CVE-2013-6239MEDIUM6.1Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers ...
CVE-2013-6234HIGH8Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users...
CVE-2013-0203MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inj...
CVE-2013-6880MEDIUM6.1Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites an...
CVE-2013-6811HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attack...
CVE-2013-3314HIGH7.5The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2)...
CVE-2013-3313HIGH7.5The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive informat...
CVE-2013-3312HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to h...
CVE-2013-3311HIGH7.5Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now