2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2013-3637MEDIUM5.4ProjectPier 0.8.8 does not use the Secure flag for cookies
CVE-2013-3636MEDIUM5.4ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
CVE-2013-3635MEDIUM5.4ProjectPier 0.8.8 has stored XSS
CVE-2013-2008MEDIUM6.1WordPress Super Cache Plugin 1.3 has XSS.
CVE-2013-0192MEDIUM4.9File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
CVE-2013-3564MEDIUM5.3The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view ...
CVE-2013-2684MEDIUM6.1Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web...
CVE-2013-2683MEDIUM5.3Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers...
CVE-2013-2682MEDIUM4.3Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain ...
CVE-2013-2675MEDIUM6.5Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could a...
CVE-2013-7054MEDIUM6.1D-Link DIR-100 4.03B07: cli.cgi XSS
CVE-2013-1422MEDIUM5.3webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
CVE-2013-2673MEDIUM6.8Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate at...
CVE-2013-2631MEDIUM5.3TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to ob...
CVE-2013-2624MEDIUM5.3Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive...
CVE-2013-2623MEDIUM6.1Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the...
CVE-2013-2622MEDIUM6.1Cross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML...
CVE-2013-2621MEDIUM6.1Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victim...
CVE-2013-3565MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allo...
CVE-2013-5114MEDIUM6.1LastPass prior to 2.5.1 allows secure wipe bypass.
CVE-2013-5113MEDIUM6.8LastPass prior to 2.5.1 has an insecure PIN implementation.
CVE-2013-5112MEDIUM4.6Evernote before 5.5.1 has insecure PIN storage
CVE-2013-4241MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow rem...
CVE-2013-4187MEDIUM6.5The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote auth...
CVE-2013-2294MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now