Vulnerabilities (CVE)

Total 395527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-5116 1 Evernote 1 Evernote 2026-06-16 6.6 MEDIUM 7.1 HIGH
Evernote prior to 5.5.1 has insecure password change
CVE-2013-5114 1 Logmein 1 Lastpass 2026-06-16 6.6 MEDIUM 6.1 MEDIUM
LastPass prior to 2.5.1 allows secure wipe bypass.
CVE-2013-5113 1 Logmein 1 Lastpass 2026-06-16 1.9 LOW 6.8 MEDIUM
LastPass prior to 2.5.1 has an insecure PIN implementation.
CVE-2013-5112 1 Evernote 1 Evernote 2026-06-16 2.1 LOW 4.6 MEDIUM
Evernote before 5.5.1 has insecure PIN storage
CVE-2013-5108 1 Rockmongo 1 Rockmongo 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the xn function in RockMongo 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) db parameter on the login page or (2) username parameter in a login.index action to index.php and other unspecified parameters.
CVE-2013-5107 1 Rockmongo 1 Rockmongo 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
CVE-2013-5106 1 Python-mode Project 1 Python-mode 2026-06-16 6.8 MEDIUM 8.8 HIGH
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
CVE-2013-5100 1 Franz Holzinger 1 Static Methods 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Static Methods since 2007 (div2007) extension before 0.10.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the t3lib_div::quoteJSvalue function.
CVE-2013-5099 1 Anchor 1 Anchor Cms 2026-06-16 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
CVE-2013-5098 2 Mikejolley, Wordpress 2 Download Monitor, Wordpress 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
CVE-2013-5097 1 Juniper 3 Junos Space, Junos Space Ja1500 Appliance, Junos Space Virtual Appliance 2026-06-16 4.0 MEDIUM N/A
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
CVE-2013-5096 1 Juniper 3 Junos Space, Junos Space Ja1500 Appliance, Junos Space Virtual Appliance 2026-06-16 4.0 MEDIUM N/A
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 863804.
CVE-2013-5095 1 Juniper 3 Junos Space, Junos Space Ja1500 Appliance, Junos Space Virtual Appliance 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka PR 884469.
CVE-2013-5094 1 Mcafee 1 Vulnerability Manager 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.
CVE-2013-5093 1 Graphite Project 1 Graphite 2026-06-16 6.8 MEDIUM N/A
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.
CVE-2013-5092 1 Algosec 1 Firewall Analyzer 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CVE-2013-5091 1 Vtiger 1 Vtiger Crm 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.
CVE-2013-5072 1 Microsoft 1 Exchange Server 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."
CVE-2013-5065 1 Microsoft 2 Windows 2003 Server, Windows Xp 2026-06-16 7.2 HIGH 7.8 HIGH
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
CVE-2013-5059 1 Microsoft 2 Office Web Apps, Sharepoint Server 2026-06-16 6.8 MEDIUM N/A
Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."