2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-10075CRITICAL9.1Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::...
CVE-2013-10056Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2013-10045Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2013-10041Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2013-20006HIGH8.7Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST ...
CVE-2013-20005MEDIUM6.9Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative act...
CVE-2013-10031HIGH7.5Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
CVE-2013-10074MEDIUM5.4Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interfac...
CVE-2013-10073HIGH8.8Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-co...
CVE-2013-10072MEDIUM6.5Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-...
CVE-2013-10071MEDIUM6.1Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashl...
CVE-2013-10070CRITICAL10PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names a...
CVE-2013-10069CRITICAL9.8The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an ...
CVE-2013-10068CRITICAL9.4Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based bu...
CVE-2013-10067CRITICAL9.4Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a...
CVE-2013-10066CRITICAL10An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an uplo...
CVE-2013-10065HIGH7.5A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH ...
CVE-2013-10064CRITICAL9.3A stack-based buffer overflow vulnerability exists in ActFax Server version 5.01. The server's RAW protocol interface fa...
CVE-2013-10054CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contai...
CVE-2013-10052HIGH8.5ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks....
CVE-2013-10063MEDIUM6.9A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded w...
CVE-2013-10062MEDIUM6.9A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware version...
CVE-2013-10061HIGH7.2An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver...
CVE-2013-10060HIGH7.2An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve...
CVE-2013-10059HIGH7.2An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now