2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2693 | — | — | 1.1% | Apr 10, 2014 | Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows r... |
| CVE-2013-2033 | — | — | 1.9% | Apr 10, 2014 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.46... |
| CVE-2013-5680 | — | — | 7.8% | Apr 6, 2014 | Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote ... |
| CVE-2013-1946 | — | — | 1.3% | Apr 6, 2014 | The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page ... |
| CVE-2013-3930 | — | — | 3.0% | Apr 4, 2014 | Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a ... |
| CVE-2013-2287 | — | — | 9.2% | Apr 4, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow... |
| CVE-2013-7352 | — | — | 0.6% | Apr 2, 2014 | Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers t... |
| CVE-2013-0735 | — | — | 2.2% | Apr 2, 2014 | Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow rem... |
| CVE-2013-3484 | — | — | 1.9% | Apr 2, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary we... |
| CVE-2013-2945 | — | — | 2.7% | Apr 2, 2014 | SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to... |
| CVE-2013-0729 | — | — | 6.2% | Apr 2, 2014 | Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary c... |
| CVE-2013-5365 | — | — | 5.2% | Apr 2, 2014 | Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition b... |
| CVE-2013-4240 | — | — | 2.8% | Apr 2, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress al... |
| CVE-2013-3213 | — | — | 3.2% | Apr 2, 2014 | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL... |
| CVE-2013-1770 | — | — | 2.2% | Apr 2, 2014 | Cross-site scripting (XSS) vulnerability in views_view.php in Ganglia Web 3.5.7 allows remote attackers to inject arbitr... |
| CVE-2013-3588 | — | — | 2.2% | Apr 2, 2014 | The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a f... |
| CVE-2013-7350 | — | — | 1.4% | Apr 1, 2014 | Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x bef... |
| CVE-2013-7348 | — | — | 0.4% | Apr 1, 2014 | Double free vulnerability in the ioctx_alloc function in fs/aio.c in the Linux kernel before 3.12.4 allows local users t... |
| CVE-2013-1869 | — | — | 1.8% | Apr 1, 2014 | CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote at... |
| CVE-2013-0662 | — | — | 22.1% | Apr 1, 2014 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow... |
| CVE-2013-7349 | — | — | 2.7% | Apr 1, 2014 | Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (... |
| CVE-2013-5640 | — | — | 2.4% | Apr 1, 2014 | Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (... |
| CVE-2013-2278 | — | — | 3.5% | Apr 1, 2014 | Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers t... |
| CVE-2013-6775 | — | — | 1.6% | Mar 31, 2014 | The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $(... |
| CVE-2013-6770 | — | — | 0.7% | Mar 31, 2014 | The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now