2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-10075 | CRITICAL | 9.1 | 0.4% | May 8, 2026 | Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::... |
| CVE-2013-10056 | — | — | — | Apr 22, 2026 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. |
| CVE-2013-10045 | — | — | — | Apr 22, 2026 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. |
| CVE-2013-10041 | — | — | — | Apr 22, 2026 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. |
| CVE-2013-20006 | HIGH | 8.7 | 0.4% | Mar 16, 2026 | Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST ... |
| CVE-2013-20005 | MEDIUM | 6.9 | 0.2% | Mar 16, 2026 | Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative act... |
| CVE-2013-10031 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks |
| CVE-2013-10074 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interfac... |
| CVE-2013-10073 | HIGH | 8.8 | 3.5% | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-co... |
| CVE-2013-10072 | MEDIUM | 6.5 | 0.7% | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-... |
| CVE-2013-10071 | MEDIUM | 6.1 | 0.5% | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashl... |
| CVE-2013-10070 | CRITICAL | 10 | 1.4% | Aug 5, 2025 | PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names a... |
| CVE-2013-10069 | CRITICAL | 9.8 | 11.9% | Aug 5, 2025 | The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an ... |
| CVE-2013-10068 | CRITICAL | 9.4 | 0.9% | Aug 5, 2025 | Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based bu... |
| CVE-2013-10067 | CRITICAL | 9.4 | 1.0% | Aug 5, 2025 | Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a... |
| CVE-2013-10066 | CRITICAL | 10 | 1.4% | Aug 5, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an uplo... |
| CVE-2013-10065 | HIGH | 7.5 | 1.1% | Aug 5, 2025 | A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH ... |
| CVE-2013-10064 | CRITICAL | 9.3 | 1.3% | Aug 5, 2025 | A stack-based buffer overflow vulnerability exists in ActFax Server version 5.01. The server's RAW protocol interface fa... |
| CVE-2013-10054 | CRITICAL | 9.3 | 1.6% | Aug 4, 2025 | An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contai... |
| CVE-2013-10052 | HIGH | 8.5 | 0.3% | Aug 4, 2025 | ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks.... |
| CVE-2013-10063 | MEDIUM | 6.9 | 0.9% | Aug 1, 2025 | A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded w... |
| CVE-2013-10062 | MEDIUM | 6.9 | 1.3% | Aug 1, 2025 | A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware version... |
| CVE-2013-10061 | HIGH | 7.2 | 4.4% | Aug 1, 2025 | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver... |
| CVE-2013-10060 | HIGH | 7.2 | 4.5% | Aug 1, 2025 | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve... |
| CVE-2013-10059 | HIGH | 7.2 | 19.1% | Aug 1, 2025 | An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now