2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5038 | — | — | 3.3% | Dec 30, 2013 | The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP a... |
| CVE-2013-5037 | — | — | 2.6% | Dec 30, 2013 | The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers... |
| CVE-2013-4858 | — | — | 13.4% | Dec 30, 2013 | Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (applica... |
| CVE-2013-6198 | — | — | 2.6% | Dec 29, 2013 | Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 ... |
| CVE-2013-6197 | — | — | 0.8% | Dec 29, 2013 | Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remot... |
| CVE-2013-6189 | — | — | 16.6% | Dec 29, 2013 | Unspecified vulnerability in the Archive Query Server in HP Application Information Optimizer (formerly HP Database Arch... |
| CVE-2013-5583 | — | — | 1.5% | Dec 29, 2013 | Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers ... |
| CVE-2013-3846 | — | — | 22.0% | Dec 29, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code o... |
| CVE-2013-2504 | — | — | 3.0% | Dec 29, 2013 | Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (a... |
| CVE-2013-7149 | — | — | 2.0% | Dec 28, 2013 | SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver ... |
| CVE-2013-6981 | — | — | 3.0% | Dec 28, 2013 | Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via frag... |
| CVE-2013-6932 | — | — | 5.7% | Dec 28, 2013 | Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote... |
| CVE-2013-6929 | — | — | 1.6% | Dec 28, 2013 | SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary ... |
| CVE-2013-6886 | — | — | 0.4% | Dec 28, 2013 | RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local users to gain privileges via a crafted argument to the (1) v... |
| CVE-2013-6812 | — | — | 0.8% | Dec 28, 2013 | The ONEDC app before 1.7 for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-m... |
| CVE-2013-6808 | — | — | 1.5% | Dec 28, 2013 | Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to injec... |
| CVE-2013-6182 | — | — | 0.5% | Dec 28, 2013 | Unquoted Windows search path vulnerability in EMC Replication Manager before 5.5 allows local users to gain privileges v... |
| CVE-2013-6181 | — | — | 0.5% | Dec 28, 2013 | EMC Watch4Net before 6.3 stores cleartext polled-device passwords in the installation repository, which allows local use... |
| CVE-2013-6006 | — | — | 2.0% | Dec 28, 2013 | Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a re... |
| CVE-2013-1096 | — | — | 2.0% | Dec 28, 2013 | Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Id... |
| CVE-2013-2179 | — | — | 2.4% | Dec 27, 2013 | X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of t... |
| CVE-2013-2030 | — | — | 0.2% | Dec 27, 2013 | keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for... |
| CVE-2013-7217 | — | — | 2.9% | Dec 26, 2013 | Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impa... |
| CVE-2013-7216 | — | — | 1.3% | Dec 24, 2013 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL comman... |
| CVE-2013-6388 | — | — | 1.8% | Dec 24, 2013 | Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now