2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4693 | MEDIUM | 6.1 | 1.3% | Dec 27, 2019 | WordPress Xorbin Digital Flash Clock 1.0 has XSS |
| CVE-2013-4691 | MEDIUM | 6.1 | 0.6% | Dec 27, 2019 | Sencha Labs Connect has XSS with connect.methodOverride() |
| CVE-2013-4665 | MEDIUM | 6.5 | 1.3% | Dec 27, 2019 | SPBAS Business Automation Software 2012 has CSRF. |
| CVE-2013-4664 | MEDIUM | 6.1 | 2.2% | Dec 27, 2019 | SPBAS Business Automation Software 2012 has XSS. |
| CVE-2013-4318 | MEDIUM | 5.4 | 0.8% | Dec 26, 2019 | File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp dir... |
| CVE-2013-0202 | MEDIUM | 6.1 | 0.9% | Dec 17, 2019 | Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitr... |
| CVE-2013-5978 | MEDIUM | 6.1 | 4.1% | Dec 11, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr... |
| CVE-2013-4303 | MEDIUM | 6.1 | 1.5% | Dec 11, 2019 | includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.... |
| CVE-2013-4968 | MEDIUM | 6.1 | 0.8% | Dec 11, 2019 | Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors relat... |
| CVE-2013-7371 | MEDIUM | 6.1 | 1.2% | Dec 11, 2019 | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete f... |
| CVE-2013-7370 | MEDIUM | 6.1 | 1.2% | Dec 11, 2019 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware |
| CVE-2013-6495 | MEDIUM | 6.1 | 0.6% | Dec 11, 2019 | JBossWeb Bayeux has reflected XSS |
| CVE-2013-4158 | MEDIUM | 6.1 | 1.2% | Dec 11, 2019 | smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) |
| CVE-2013-1689 | MEDIUM | 6.5 | 0.8% | Dec 10, 2019 | Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handli... |
| CVE-2013-4184 | MEDIUM | 5.5 | 0.5% | Dec 10, 2019 | Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks |
| CVE-2013-0342 | MEDIUM | 4.3 | 1.5% | Dec 9, 2019 | The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote atta... |
| CVE-2013-0326 | MEDIUM | 5.5 | 0.4% | Dec 5, 2019 | OpenStack nova base images permissions are world readable |
| CVE-2013-0283 | MEDIUM | 5.4 | 0.6% | Dec 5, 2019 | Katello: Username in Notification page has cross site scripting |
| CVE-2013-0163 | MEDIUM | 5.5 | 0.3% | Dec 5, 2019 | OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS |
| CVE-2013-4411 | MEDIUM | 4.3 | 1.4% | Dec 3, 2019 | Review Board: URL processing gives unauthorized users access to review lists |
| CVE-2013-4235 | MEDIUM | 4.7 | 0.3% | Dec 3, 2019 | shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees |
| CVE-2013-2101 | MEDIUM | 5.4 | 0.6% | Dec 3, 2019 | Katello has multiple XSS issues in various entities |
| CVE-2013-2625 | MEDIUM | 6.5 | 1.3% | Nov 27, 2019 | An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0... |
| CVE-2013-6879 | MEDIUM | 5.3 | 1.1% | Nov 22, 2019 | The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information ... |
| CVE-2013-6878 | MEDIUM | 6.1 | 0.8% | Nov 22, 2019 | Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remot... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now