2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2013-6239MEDIUM6.1Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers ...
CVE-2013-0203MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inj...
CVE-2013-6880MEDIUM6.1Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites an...
CVE-2013-2092MEDIUM6.1Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in f...
CVE-2013-0195MEDIUM6.1Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns...
CVE-2013-0194MEDIUM6.1Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns...
CVE-2013-0193MEDIUM6.1Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns...
CVE-2013-4584MEDIUM5.9Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP ...
CVE-2013-4106MEDIUM6.1A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
CVE-2013-4109MEDIUM6.1An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
CVE-2013-3097MEDIUM6.1Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
CVE-2013-4275MEDIUM5.4Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3....
CVE-2013-3516MEDIUM6.5NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows att...
CVE-2013-3517MEDIUM5.4Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
CVE-2013-1820MEDIUM5.5tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
CVE-2013-1811MEDIUM4.3An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
CVE-2013-1429MEDIUM6.3Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
CVE-2013-1426MEDIUM6.1Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web...
CVE-2013-1425MEDIUM5.5ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
CVE-2013-5123MEDIUM5.9The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh...
CVE-2013-6275MEDIUM6.5Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
CVE-2013-5661MEDIUM5.9Cache Poisoning issue exists in DNS Response Rate Limiting.
CVE-2013-6461MEDIUM6.5Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
CVE-2013-6460MEDIUM6.5Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
CVE-2013-6365MEDIUM5.3Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now