2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2013-4693MEDIUM6.1WordPress Xorbin Digital Flash Clock 1.0 has XSS
CVE-2013-4691MEDIUM6.1Sencha Labs Connect has XSS with connect.methodOverride()
CVE-2013-4665MEDIUM6.5SPBAS Business Automation Software 2012 has CSRF.
CVE-2013-4664MEDIUM6.1SPBAS Business Automation Software 2012 has XSS.
CVE-2013-4318MEDIUM5.4File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp dir...
CVE-2013-0202MEDIUM6.1Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitr...
CVE-2013-5978MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr...
CVE-2013-4303MEDIUM6.1includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21....
CVE-2013-4968MEDIUM6.1Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors relat...
CVE-2013-7371MEDIUM6.1node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete f...
CVE-2013-7370MEDIUM6.1node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
CVE-2013-6495MEDIUM6.1JBossWeb Bayeux has reflected XSS
CVE-2013-4158MEDIUM6.1smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
CVE-2013-1689MEDIUM6.5Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handli...
CVE-2013-4184MEDIUM5.5Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
CVE-2013-0342MEDIUM4.3The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote atta...
CVE-2013-0326MEDIUM5.5OpenStack nova base images permissions are world readable
CVE-2013-0283MEDIUM5.4Katello: Username in Notification page has cross site scripting
CVE-2013-0163MEDIUM5.5OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
CVE-2013-4411MEDIUM4.3Review Board: URL processing gives unauthorized users access to review lists
CVE-2013-4235MEDIUM4.7shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
CVE-2013-2101MEDIUM5.4Katello has multiple XSS issues in various entities
CVE-2013-2625MEDIUM6.5An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0...
CVE-2013-6879MEDIUM5.3The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information ...
CVE-2013-6878MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remot...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now