2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4844 | — | — | 5.5% | Nov 29, 2013 | Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, 9.31, and 9.32, and ServiceCenter 6.2.8, allows remote... |
| CVE-2013-6712 | — | — | 4.6% | Nov 28, 2013 | The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of Date... |
| CVE-2013-6322 | — | — | 0.9% | Nov 28, 2013 | Cross-site scripting (XSS) vulnerability in Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 8.0 ... |
| CVE-2013-5912 | — | — | 31.4% | Nov 28, 2013 | VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute... |
| CVE-2013-5957 | — | — | 2.1% | Nov 27, 2013 | Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, ... |
| CVE-2013-4624 | — | — | 1.4% | Nov 27, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec... |
| CVE-2013-4617 | — | — | 1.3% | Nov 27, 2013 | Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes ... |
| CVE-2013-3920 | — | — | 0.8% | Nov 27, 2013 | Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2 allows remote authenticated users to inject arbitrary... |
| CVE-2013-6383 | — | — | 0.5% | Nov 27, 2013 | The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP... |
| CVE-2013-6382 | — | — | 0.6% | Nov 27, 2013 | Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a den... |
| CVE-2013-6381 | — | — | 0.6% | Nov 27, 2013 | Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.... |
| CVE-2013-6380 | — | — | 0.6% | Nov 27, 2013 | The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly va... |
| CVE-2013-6378 | — | — | 0.4% | Nov 27, 2013 | The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows loca... |
| CVE-2013-4036 | — | — | 0.8% | Nov 27, 2013 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Managem... |
| CVE-2013-3394 | — | — | 0.9% | Nov 27, 2013 | Cross-site scripting (XSS) vulnerability in the web interface in Cisco Prime Network Registrar 8.1 and earlier allows re... |
| CVE-2013-6875 | — | — | 3.2% | Nov 26, 2013 | SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allo... |
| CVE-2013-6874 | — | — | 6.0% | Nov 26, 2013 | Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a l... |
| CVE-2013-6873 | — | — | 2.3% | Nov 26, 2013 | SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arb... |
| CVE-2013-3923 | — | — | 1.9% | Nov 26, 2013 | Directory traversal vulnerability in SavySoda WiFi HD Free before 7.0 allows remote attackers to read arbitrary files vi... |
| CVE-2013-4525 | — | — | 1.0% | Nov 26, 2013 | Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.... |
| CVE-2013-4524 | — | — | 1.8% | Nov 26, 2013 | Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x ... |
| CVE-2013-4523 | — | — | 1.0% | Nov 26, 2013 | Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before ... |
| CVE-2013-4522 | — | — | 1.5% | Nov 26, 2013 | lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send ... |
| CVE-2013-6870 | — | — | 1.8% | Nov 25, 2013 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.6 allows remote attackers to inject arbitrar... |
| CVE-2013-6374 | — | — | 1.0% | Nov 25, 2013 | Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote aut... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now