2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2627 | — | — | 1.2% | Dec 21, 2013 | SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to e... |
| CVE-2013-7190 | — | — | 3.9% | Dec 20, 2013 | Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr... |
| CVE-2013-7189 | — | — | 1.4% | Dec 20, 2013 | Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary... |
| CVE-2013-7188 | — | — | 1.3% | Dec 20, 2013 | Cross-site scripting (XSS) vulnerability in KBKP Software HostBill before 2013-12-14 allows remote attackers to inject a... |
| CVE-2013-7187 | — | — | 4.8% | Dec 20, 2013 | SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers ... |
| CVE-2013-7186 | — | — | 11.6% | Dec 20, 2013 | Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long ... |
| CVE-2013-6767 | — | — | 1.3% | Dec 20, 2013 | Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary co... |
| CVE-2013-4576 | — | — | 0.5% | Dec 20, 2013 | GnuPG 1.x before 1.4.16 generates RSA keys using sequences of introductions with certain patterns that introduce a side ... |
| CVE-2013-7136 | — | — | 4.2% | Dec 19, 2013 | The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK pa... |
| CVE-2013-7114 | — | — | 2.2% | Dec 19, 2013 | Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 di... |
| CVE-2013-7113 | — | — | 2.2% | Dec 19, 2013 | epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global v... |
| CVE-2013-7112 | — | — | 2.3% | Dec 19, 2013 | The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 an... |
| CVE-2013-7100 | — | — | 14.7% | Dec 19, 2013 | Buffer overflow in the unpacksms16 function in apps/app_sms.c in Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before... |
| CVE-2013-6976 | — | — | 3.7% | Dec 19, 2013 | Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers t... |
| CVE-2013-6877 | — | — | 11.3% | Dec 19, 2013 | Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738... |
| CVE-2013-6717 | — | — | 2.4% | Dec 19, 2013 | The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP... |
| CVE-2013-6178 | — | — | 1.4% | Dec 19, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.4 SP1 allow remote attackers to i... |
| CVE-2013-5462 | — | — | 1.8% | Dec 19, 2013 | IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP0... |
| CVE-2013-5452 | — | — | 1.0% | Dec 19, 2013 | IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP reque... |
| CVE-2013-5426 | — | — | 0.5% | Dec 19, 2013 | Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and... |
| CVE-2013-5422 | — | — | 1.2% | Dec 19, 2013 | The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when... |
| CVE-2013-4418 | — | — | — | Dec 19, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2013-4403 | — | — | — | Dec 19, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4404. Reason: This candidate is a reservation ... |
| CVE-2013-7086 | — | — | 3.5% | Dec 19, 2013 | The message function in lib/webbynode/notify.rb in the Webbynode gem 1.0.5.3 and earlier for Ruby allows context-depende... |
| CVE-2013-7067 | — | — | 1.2% | Dec 19, 2013 | The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback s... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now