Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 860 High, 2,913 Medium, 517 Low, 1 Unrated.

CVE-2013-3572

Published Dec 31, 2013

Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0264

Published Dec 31, 2013

op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via unspecified vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0263

Published Dec 31, 2013

monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error m…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0262

Published Dec 31, 2013

op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-0261

Published Dec 31, 2013

license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the times…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6987

Published Dec 31, 2013

Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6459

Published Dec 31, 2013

Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving genera…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5573

Published Dec 31, 2013

Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7242

Published Dec 31, 2013

SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7241

Published Dec 31, 2013

Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6983

Published Dec 31, 2013

SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7209

Published Dec 30, 2013

Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for requ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7233

Published Dec 30, 2013

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7232

Published Dec 30, 2013

SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7231

Published Dec 30, 2013

Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or H…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-5222

Published Dec 30, 2013

Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 5,187 CVEsPage 1 of 208