2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2602 | — | — | 3.6% | Jun 6, 2014 | Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote... |
| CVE-2013-0250 | — | — | 3.1% | Jun 6, 2014 | The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, w... |
| CVE-2013-4860 | — | — | 2.0% | Jun 5, 2014 | Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote... |
| CVE-2013-3739 | — | — | 3.7% | Jun 5, 2014 | Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read ... |
| CVE-2013-2618 | — | — | 4.7% | Jun 5, 2014 | Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inj... |
| CVE-2013-2130 | — | — | 2.2% | Jun 5, 2014 | ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted ... |
| CVE-2013-0733 | — | — | 5.1% | Jun 5, 2014 | Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local user... |
| CVE-2013-0304 | — | — | 1.0% | Jun 5, 2014 | ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to ... |
| CVE-2013-0302 | — | — | 1.3% | Jun 5, 2014 | Unspecified vulnerability in ownCloud Server before 4.0.12 allows remote attackers to obtain sensitive information via u... |
| CVE-2013-1941 | — | — | 1.1% | Jun 4, 2014 | The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time func... |
| CVE-2013-0204 | — | — | 0.9% | Jun 4, 2014 | settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via... |
| CVE-2013-0191 | — | — | 1.8% | Jun 3, 2014 | libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allo... |
| CVE-2013-7387 | — | — | 5.0% | Jun 2, 2014 | Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v... |
| CVE-2013-7386 | — | — | 4.4% | Jun 2, 2014 | Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.... |
| CVE-2013-6470 | — | — | 1.9% | Jun 2, 2014 | The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Re... |
| CVE-2013-6433 | — | — | 3.3% | Jun 2, 2014 | The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configurati... |
| CVE-2013-4596 | — | — | 1.2% | Jun 2, 2014 | The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote a... |
| CVE-2013-3476 | — | — | 1.1% | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows ... |
| CVE-2013-3258 | — | — | 1.1% | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attacker... |
| CVE-2013-3257 | — | — | 1.1% | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote att... |
| CVE-2013-2710 | — | — | 1.1% | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows... |
| CVE-2013-2298 | — | — | 2.6% | Jun 2, 2014 | Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a cr... |
| CVE-2013-2019 | — | — | 2.3% | Jun 2, 2014 | Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple... |
| CVE-2013-2014 | — | — | 3.2% | Jun 2, 2014 | OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and... |
| CVE-2013-1818 | — | — | 2.1% | Jun 2, 2014 | maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now