2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7247 | — | — | 2.7% | Jan 26, 2014 | cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows... |
| CVE-2013-7137 | CRITICAL | 9.8 | 16.1% | Jan 26, 2014 | The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and... |
| CVE-2013-6891 | — | — | 0.4% | Jan 26, 2014 | lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary fil... |
| CVE-2013-6853 | — | — | 1.9% | Jan 26, 2014 | Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac... |
| CVE-2013-5364 | — | — | 0.4% | Jan 26, 2014 | Secunia CSI Agent 6.0.0.15017 and earlier, 6.0.1.1007 and earlier, and 7.0.0.21 and earlier, when running on Red Hat Lin... |
| CVE-2013-6458 | — | — | 0.6% | Jan 24, 2014 | Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) v... |
| CVE-2013-6457 | — | — | 0.7% | Jan 24, 2014 | The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not pr... |
| CVE-2013-6434 | — | — | 1.0% | Jan 24, 2014 | The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client inv... |
| CVE-2013-2192 | — | — | 1.1% | Jan 24, 2014 | The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, whe... |
| CVE-2013-1853 | — | — | 0.4% | Jan 24, 2014 | Almanah Diary 0.9.0 and 0.10.0 does not encrypt the database when closed, which allows local users to obtain sensitive i... |
| CVE-2013-1886 | — | — | 2.2% | Jan 24, 2014 | Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possib... |
| CVE-2013-1885 | — | — | 1.2% | Jan 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate Syst... |
| CVE-2013-7317 | — | — | 1.0% | Jan 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary w... |
| CVE-2013-7316 | — | — | 1.9% | Jan 24, 2014 | Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject... |
| CVE-2013-7184 | — | — | 2.3% | Jan 24, 2014 | Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption... |
| CVE-2013-5350 | — | — | 1.5% | Jan 24, 2014 | The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in... |
| CVE-2013-7175 | — | — | 1.3% | Jan 24, 2014 | Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated use... |
| CVE-2013-6030 | — | — | 2.9% | Jan 24, 2014 | Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch wi... |
| CVE-2013-5669 | — | — | 2.2% | Jan 24, 2014 | The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which al... |
| CVE-2013-5668 | — | — | 2.1% | Jan 24, 2014 | The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the adm... |
| CVE-2013-5667 | — | — | 4.2% | Jan 24, 2014 | The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid... |
| CVE-2013-7315 | — | — | 3.4% | Jan 23, 2014 | The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolutio... |
| CVE-2013-7048 | — | — | 0.5% | Jan 23, 2014 | OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissio... |
| CVE-2013-6934 | — | — | 28.2% | Jan 23, 2014 | The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media P... |
| CVE-2013-6933 | — | — | 17.4% | Jan 23, 2014 | The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in V... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now