2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7408 | — | — | 2.0% | Oct 26, 2014 | F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to ... |
| CVE-2013-6796 | — | — | 6.3% | Oct 26, 2014 | The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic... |
| CVE-2013-1641 | — | — | 3.7% | Oct 26, 2014 | Directory traversal vulnerability in the zip download functionality in QuiXplorer before 2.5.5 allows remote attackers t... |
| CVE-2013-4594 | — | — | 1.0% | Oct 25, 2014 | The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allo... |
| CVE-2013-7407 | — | — | 0.6% | Oct 22, 2014 | Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the auth... |
| CVE-2013-7406 | — | — | 1.3% | Oct 21, 2014 | SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2013-7330 | — | — | 1.6% | Oct 17, 2014 | Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related ... |
| CVE-2013-4488 | — | — | 1.0% | Oct 10, 2014 | libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to s... |
| CVE-2013-7329 | — | — | 1.9% | Oct 6, 2014 | The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attacke... |
| CVE-2013-1436 | — | — | 9.0% | Oct 6, 2014 | The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands... |
| CVE-2013-6496 | — | — | 1.8% | Oct 6, 2014 | Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, ... |
| CVE-2013-2645 | — | — | 3.0% | Oct 6, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_12... |
| CVE-2013-2644 | — | — | — | Oct 5, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2645, CVE-2014-2644. Reason: this ID was inten... |
| CVE-2013-3092 | — | — | 2.2% | Sep 29, 2014 | The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors rela... |
| CVE-2013-3089 | — | — | 0.6% | Sep 29, 2014 | Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers t... |
| CVE-2013-3086 | — | — | 0.6% | Sep 29, 2014 | Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hij... |
| CVE-2013-3083 | — | — | 2.2% | Sep 29, 2014 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attac... |
| CVE-2013-3068 | — | — | 0.6% | Sep 29, 2014 | Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hij... |
| CVE-2013-3066 | — | — | 2.1% | Sep 29, 2014 | Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain se... |
| CVE-2013-3065 | — | — | 0.8% | Sep 29, 2014 | Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 ... |
| CVE-2013-3064 | — | — | 1.3% | Sep 29, 2014 | Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote att... |
| CVE-2013-2586 | — | — | 5.2% | Sep 29, 2014 | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp ... |
| CVE-2013-2100 | — | — | 1.6% | Sep 29, 2014 | The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 c... |
| CVE-2013-1874 | — | — | 0.4% | Sep 29, 2014 | Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Tr... |
| CVE-2013-4444 | — | — | 14.0% | Sep 12, 2014 | Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now