2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-2073——Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers ...
CVE-2013-6323——Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x bef...
CVE-2013-7374——The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 d...
CVE-2013-4121——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-1807——PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web docu...
CVE-2013-1806——Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include an...
CVE-2013-1805——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-201...
CVE-2013-6990——FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
CVE-2013-6445——Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash pas...
CVE-2013-7373——Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to def...
CVE-2013-7372——The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/cryp...
CVE-2013-1804——Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitr...
CVE-2013-7302——Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, whe...
CVE-2013-7284——The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execu...
CVE-2013-7273——GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a deni...
CVE-2013-7259——Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentic...
CVE-2013-7236——Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unic...
CVE-2013-7235——Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users vi...
CVE-2013-7234——Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks v...
CVE-2013-7221——The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Ent...
CVE-2013-7220——js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbit...
CVE-2013-7134——Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by levera...
CVE-2013-7111——The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 ...
CVE-2013-7068——The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restr...
CVE-2013-7066——The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles b...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now