2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4057 | — | — | 0.7% | Mar 16, 2014 | Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 F... |
| CVE-2013-0301 | — | — | 0.6% | Mar 14, 2014 | Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 all... |
| CVE-2013-0300 | — | — | 0.4% | Mar 14, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to hija... |
| CVE-2013-0299 | — | — | 0.6% | Mar 14, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote... |
| CVE-2013-4963 | — | — | 0.8% | Mar 14, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers... |
| CVE-2013-2150 | — | — | 1.2% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow... |
| CVE-2013-2149 | — | — | 1.2% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.16 and 5.x before 5.0.7 allow remote authenti... |
| CVE-2013-2089 | — | — | 1.3% | Mar 14, 2014 | Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP c... |
| CVE-2013-2086 | — | — | 1.8% | Mar 14, 2014 | The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitiv... |
| CVE-2013-2085 | — | — | 1.5% | Mar 14, 2014 | Directory traversal vulnerability in apps/files_trashbin/index.php in ownCloud Server before 5.0.6 allows remote authent... |
| CVE-2013-2048 | — | — | 1.6% | Mar 14, 2014 | ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary ... |
| CVE-2013-2047 | — | — | 0.4% | Mar 14, 2014 | The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password param... |
| CVE-2013-2044 | — | — | 1.6% | Mar 14, 2014 | Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect u... |
| CVE-2013-2043 | — | — | 1.4% | Mar 14, 2014 | apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a ... |
| CVE-2013-2042 | — | — | 1.2% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0... |
| CVE-2013-2041 | — | — | 1.2% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x before 5.0.6 allow remote authenticated users to i... |
| CVE-2013-2040 | — | — | 1.2% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0... |
| CVE-2013-2039 | — | — | 2.0% | Mar 14, 2014 | Directory traversal vulnerability in lib/files/view.php in ownCloud before 4.0.15, 4.5.x 4.5.11, and 5.x before 5.0.6 al... |
| CVE-2013-1963 | — | — | 1.4% | Mar 14, 2014 | The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contact... |
| CVE-2013-1939 | — | — | 1.8% | Mar 14, 2014 | The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when ... |
| CVE-2013-1851 | — | — | 1.2% | Mar 14, 2014 | Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_mi... |
| CVE-2013-1850 | — | — | 1.2% | Mar 14, 2014 | Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCl... |
| CVE-2013-1822 | — | — | 0.7% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with... |
| CVE-2013-1399 | — | — | 0.6% | Mar 14, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and ... |
| CVE-2013-1398 | — | — | 1.5% | Mar 14, 2014 | The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of priva... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now