2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6239 | MEDIUM | 6.1 | 1.4% | Nov 22, 2019 | Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers ... |
| CVE-2013-0203 | MEDIUM | 5.4 | 0.7% | Nov 22, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inj... |
| CVE-2013-6880 | MEDIUM | 6.1 | 1.4% | Nov 22, 2019 | Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites an... |
| CVE-2013-2092 | MEDIUM | 6.1 | 1.3% | Nov 20, 2019 | Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in f... |
| CVE-2013-0195 | MEDIUM | 6.1 | 1.2% | Nov 20, 2019 | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns... |
| CVE-2013-0194 | MEDIUM | 6.1 | 1.2% | Nov 20, 2019 | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns... |
| CVE-2013-0193 | MEDIUM | 6.1 | 1.2% | Nov 20, 2019 | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns... |
| CVE-2013-4584 | MEDIUM | 5.9 | 1.5% | Nov 15, 2019 | Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP ... |
| CVE-2013-4106 | MEDIUM | 6.1 | 1.5% | Nov 14, 2019 | A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22. |
| CVE-2013-4109 | MEDIUM | 6.1 | 1.7% | Nov 14, 2019 | An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165. |
| CVE-2013-3097 | MEDIUM | 6.1 | 1.5% | Nov 13, 2019 | Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router. |
| CVE-2013-4275 | MEDIUM | 5.4 | 1.0% | Nov 13, 2019 | Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.... |
| CVE-2013-3516 | MEDIUM | 6.5 | 0.7% | Nov 13, 2019 | NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows att... |
| CVE-2013-3517 | MEDIUM | 5.4 | 0.6% | Nov 13, 2019 | Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L. |
| CVE-2013-1820 | MEDIUM | 5.5 | 0.4% | Nov 8, 2019 | tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. |
| CVE-2013-1811 | MEDIUM | 4.3 | 1.0% | Nov 7, 2019 | An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". |
| CVE-2013-1429 | MEDIUM | 6.3 | 1.3% | Nov 7, 2019 | Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. |
| CVE-2013-1426 | MEDIUM | 6.1 | 1.0% | Nov 7, 2019 | Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web... |
| CVE-2013-1425 | MEDIUM | 5.5 | 0.3% | Nov 7, 2019 | ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. |
| CVE-2013-5123 | MEDIUM | 5.9 | 8.0% | Nov 5, 2019 | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh... |
| CVE-2013-6275 | MEDIUM | 6.5 | 2.1% | Nov 5, 2019 | Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. |
| CVE-2013-5661 | MEDIUM | 5.9 | 3.5% | Nov 5, 2019 | Cache Poisoning issue exists in DNS Response Rate Limiting. |
| CVE-2013-6461 | MEDIUM | 6.5 | 2.2% | Nov 5, 2019 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits |
| CVE-2013-6460 | MEDIUM | 6.5 | 2.1% | Nov 5, 2019 | Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents |
| CVE-2013-6365 | MEDIUM | 5.3 | 1.1% | Nov 5, 2019 | Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now