2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2013-5116HIGH7.1Evernote prior to 5.5.1 has insecure password change
CVE-2013-3322HIGH7.2NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot ...
CVE-2013-1352HIGH7.5Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.
CVE-2013-0725HIGH7.8ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities
CVE-2013-0291HIGH7.5NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
CVE-2013-3321HIGH7.5NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially cra...
CVE-2013-2574HIGH7.5An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo...
CVE-2013-2572HIGH7.5A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 d...
CVE-2013-2569HIGH7.5A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is dis...
CVE-2013-2567HIGH7.5An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded...
CVE-2013-1602HIGH7.5An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP ses...
CVE-2013-3212HIGH8.1vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote atta...
CVE-2013-3093HIGH8.8ASUS RT-N56U devices allow CSRF.
CVE-2013-3074HIGH7.5NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device...
CVE-2013-4863HIGH8.8The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a...
CVE-2013-4862HIGH8.1MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to...
CVE-2013-4583HIGH8.8The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise...
CVE-2013-1895HIGH7.5The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to ...
CVE-2013-2499HIGH7.5SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via sp...
CVE-2013-2474HIGH7.5Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' paramete...
CVE-2013-2267HIGH7.2PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbit...
CVE-2013-6056HIGH7.5OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
CVE-2013-5659HIGH7.5Wiz 5.0.3 has a user mode write access violation
CVE-2013-1598HIGH8.8A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to th...
CVE-2013-1594HIGH7.5An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wire...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now