2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2758 | — | — | 6.5% | May 23, 2014 | Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C us... |
| CVE-2013-2757 | — | — | 2.7% | May 23, 2014 | Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC po... |
| CVE-2013-2756 | — | — | 5.8% | May 23, 2014 | Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C al... |
| CVE-2013-2713 | — | — | 1.4% | May 23, 2014 | Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers... |
| CVE-2013-2712 | — | — | 1.8% | May 23, 2014 | Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attacker... |
| CVE-2013-1864 | — | — | 2.9% | May 23, 2014 | The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion ... |
| CVE-2013-1668 | — | — | 7.0% | May 23, 2014 | The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary com... |
| CVE-2013-0289 | — | — | 1.3% | May 23, 2014 | Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN)... |
| CVE-2013-2107 | — | — | 3.2% | May 23, 2014 | Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote at... |
| CVE-2013-7383 | — | — | 2.9% | May 20, 2014 | x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain pr... |
| CVE-2013-4380 | — | — | 0.9% | May 20, 2014 | Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.... |
| CVE-2013-4347 | — | — | 2.4% | May 20, 2014 | The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random ... |
| CVE-2013-4346 | — | — | 2.4% | May 20, 2014 | The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to... |
| CVE-2013-4321 | — | — | 1.1% | May 20, 2014 | The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors ... |
| CVE-2013-4320 | — | — | 1.0% | May 20, 2014 | The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions,... |
| CVE-2013-4250 | — | — | 1.2% | May 20, 2014 | The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do... |
| CVE-2013-6975 | — | — | 0.5% | May 20, 2014 | Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to... |
| CVE-2013-7385 | — | — | 1.3% | May 19, 2014 | LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is gen... |
| CVE-2013-7384 | — | — | 2.4% | May 19, 2014 | UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and cra... |
| CVE-2013-7040 | — | — | 3.3% | May 19, 2014 | Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute h... |
| CVE-2013-7033 | — | — | 1.2% | May 19, 2014 | LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/c... |
| CVE-2013-6994 | — | — | 1.2% | May 19, 2014 | OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session... |
| CVE-2013-6807 | — | — | 0.6% | May 19, 2014 | The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle att... |
| CVE-2013-6806 | — | — | 1.0% | May 19, 2014 | OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain s... |
| CVE-2013-6805 | — | — | 0.7% | May 19, 2014 | OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to d... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now