2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6323 | — | — | 1.6% | May 1, 2014 | Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x bef... |
| CVE-2013-7374 | — | — | 0.4% | May 1, 2014 | The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 d... |
| CVE-2013-4121 | — | — | — | May 1, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2013-1807 | — | — | 7.6% | Apr 30, 2014 | PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web docu... |
| CVE-2013-1806 | — | — | 7.8% | Apr 30, 2014 | Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include an... |
| CVE-2013-1805 | — | — | — | Apr 30, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-201... |
| CVE-2013-6990 | — | — | 1.1% | Apr 30, 2014 | FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface. |
| CVE-2013-6445 | — | — | 1.1% | Apr 30, 2014 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash pas... |
| CVE-2013-7373 | — | — | 1.1% | Apr 29, 2014 | Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to def... |
| CVE-2013-7372 | — | — | 2.3% | Apr 29, 2014 | The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/cryp... |
| CVE-2013-1804 | — | — | 4.4% | Apr 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitr... |
| CVE-2013-7302 | — | — | 1.3% | Apr 29, 2014 | Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, whe... |
| CVE-2013-7284 | — | — | 2.8% | Apr 29, 2014 | The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execu... |
| CVE-2013-7273 | — | — | 0.4% | Apr 29, 2014 | GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a deni... |
| CVE-2013-7259 | — | — | 1.3% | Apr 29, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentic... |
| CVE-2013-7236 | — | — | 1.5% | Apr 29, 2014 | Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unic... |
| CVE-2013-7235 | — | — | 1.5% | Apr 29, 2014 | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users vi... |
| CVE-2013-7234 | — | — | 1.2% | Apr 29, 2014 | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks v... |
| CVE-2013-7221 | — | — | 0.4% | Apr 29, 2014 | The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Ent... |
| CVE-2013-7220 | — | — | 0.4% | Apr 29, 2014 | js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbit... |
| CVE-2013-7134 | — | — | 2.3% | Apr 29, 2014 | Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by levera... |
| CVE-2013-7111 | — | — | 1.5% | Apr 29, 2014 | The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 ... |
| CVE-2013-7066 | — | — | 1.1% | Apr 29, 2014 | The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles b... |
| CVE-2013-7068 | — | — | 1.0% | Apr 29, 2014 | The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restr... |
| CVE-2013-7065 | — | — | 1.2% | Apr 29, 2014 | The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions a... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now