2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4501 | — | — | 1.4% | May 13, 2014 | The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz ... |
| CVE-2013-4500 | — | — | 1.1% | May 13, 2014 | The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the "view any quiz results" or ... |
| CVE-2013-4490 | — | — | 42.1% | May 13, 2014 | The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x... |
| CVE-2013-2705 | — | — | 1.1% | May 13, 2014 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordP... |
| CVE-2013-2692 | — | — | 1.0% | May 13, 2014 | Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows ... |
| CVE-2013-1407 | — | — | 2.1% | May 13, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plu... |
| CVE-2013-6472 | — | — | 1.3% | May 12, 2014 | MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information abo... |
| CVE-2013-6454 | — | — | 1.5% | May 12, 2014 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow... |
| CVE-2013-6453 | — | — | 1.4% | May 12, 2014 | MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allow... |
| CVE-2013-6452 | — | — | 1.0% | May 12, 2014 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow... |
| CVE-2013-5984 | — | — | 2.8% | May 12, 2014 | Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote ... |
| CVE-2013-5749 | — | — | 1.5% | May 12, 2014 | Cross-site scripting (XSS) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows ... |
| CVE-2013-5748 | — | — | 2.0% | May 12, 2014 | Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 ... |
| CVE-2013-5671 | — | — | 2.2% | May 12, 2014 | lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary c... |
| CVE-2013-4772 | — | — | 4.2% | May 12, 2014 | D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to ... |
| CVE-2013-4581 | — | — | 2.1% | May 12, 2014 | GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 a... |
| CVE-2013-4580 | — | — | 1.3% | May 12, 2014 | GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, al... |
| CVE-2013-4577 | — | — | 0.4% | May 12, 2014 | A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain pas... |
| CVE-2013-4574 | — | — | 1.4% | May 12, 2014 | Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.2... |
| CVE-2013-4571 | — | — | 1.4% | May 12, 2014 | Buffer overflow in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.... |
| CVE-2013-4570 | — | — | 1.7% | May 12, 2014 | The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x befor... |
| CVE-2013-6220 | — | — | 2.5% | May 10, 2014 | Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0, 9.10, and 9.20 allows remote attackers... |
| CVE-2013-5916 | — | — | 2.0% | May 8, 2014 | Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the W... |
| CVE-2013-7041 | — | — | 2.5% | May 8, 2014 | The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for atta... |
| CVE-2013-6889 | — | — | 0.5% | May 8, 2014 | GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option. |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now