2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2057 | CRITICAL | 9.8 | 2.1% | Feb 11, 2020 | YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability |
| CVE-2013-1760 | MEDIUM | 6.1 | 1.1% | Feb 11, 2020 | The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities |
| CVE-2013-1607 | CRITICAL | 9.8 | 2.7% | Feb 11, 2020 | Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability |
| CVE-2013-0517 | HIGH | 7.8 | 0.6% | Feb 11, 2020 | A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 ... |
| CVE-2013-1359 | CRITICAL | 9.8 | 89.1% | Feb 11, 2020 | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5... |
| CVE-2013-0803 | CRITICAL | 9.8 | 74.5% | Feb 11, 2020 | A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb... |
| CVE-2013-4535 | HIGH | 8.8 | 1.0% | Feb 11, 2020 | The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary fi... |
| CVE-2013-1360 | CRITICAL | 9.8 | 22.7% | Feb 11, 2020 | An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7... |
| CVE-2013-5945 | CRITICAL | 9.8 | 9.5% | Feb 11, 2020 | Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.0... |
| CVE-2013-4269 | — | — | — | Feb 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4267. Reason: This issue was MERGED into CVE-201... |
| CVE-2013-4268 | — | — | — | Feb 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4267. Reason: This issue was MERGED into CVE-201... |
| CVE-2013-4267 | CRITICAL | 9.8 | 4.1% | Feb 11, 2020 | Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archi... |
| CVE-2013-2109 | HIGH | 8.8 | 1.8% | Feb 10, 2020 | WordPress plugin wp-cleanfix has Remote Code Execution |
| CVE-2013-2108 | MEDIUM | 5.4 | 2.2% | Feb 10, 2020 | WordPress WP Cleanfix Plugin 2.4.4 has CSRF |
| CVE-2013-1353 | MEDIUM | 5.4 | 0.6% | Feb 10, 2020 | Orange HRM 2.7.1 allows XSS via the vacancy name. |
| CVE-2013-3096 | MEDIUM | 5.9 | 1.3% | Feb 7, 2020 | D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability. |
| CVE-2013-3091 | CRITICAL | 9.8 | 3.7% | Feb 7, 2020 | An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authenticatio... |
| CVE-2013-3067 | MEDIUM | 5.4 | 0.8% | Feb 7, 2020 | Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS. |
| CVE-2013-4335 | CRITICAL | 9.8 | 2.5% | Feb 7, 2020 | opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities |
| CVE-2013-3637 | MEDIUM | 5.4 | 0.6% | Feb 7, 2020 | ProjectPier 0.8.8 does not use the Secure flag for cookies |
| CVE-2013-3636 | MEDIUM | 5.4 | 1.0% | Feb 7, 2020 | ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag |
| CVE-2013-3635 | MEDIUM | 5.4 | 0.6% | Feb 7, 2020 | ProjectPier 0.8.8 has stored XSS |
| CVE-2013-3629 | HIGH | 8.8 | 43.1% | Feb 7, 2020 | ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution |
| CVE-2013-3628 | HIGH | 8.8 | 67.5% | Feb 7, 2020 | Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability |
| CVE-2013-3591 | HIGH | 8.8 | 43.1% | Feb 7, 2020 | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now