2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3684CRITICAL9.8NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
CVE-2013-2057CRITICAL9.8YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
CVE-2013-1760MEDIUM6.1The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities
CVE-2013-1607CRITICAL9.8Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability
CVE-2013-0517HIGH7.8A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 ...
CVE-2013-1359CRITICAL9.8An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5...
CVE-2013-0803CRITICAL9.8A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb...
CVE-2013-4535HIGH8.8The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary fi...
CVE-2013-1360CRITICAL9.8An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7...
CVE-2013-5945CRITICAL9.8Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.0...
CVE-2013-4269——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4267. Reason: This issue was MERGED into CVE-201...
CVE-2013-4268——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4267. Reason: This issue was MERGED into CVE-201...
CVE-2013-4267CRITICAL9.8Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archi...
CVE-2013-2109HIGH8.8WordPress plugin wp-cleanfix has Remote Code Execution
CVE-2013-2108MEDIUM5.4WordPress WP Cleanfix Plugin 2.4.4 has CSRF
CVE-2013-1353MEDIUM5.4Orange HRM 2.7.1 allows XSS via the vacancy name.
CVE-2013-3096MEDIUM5.9D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
CVE-2013-3091CRITICAL9.8An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authenticatio...
CVE-2013-3067MEDIUM5.4Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
CVE-2013-4335CRITICAL9.8opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
CVE-2013-3637MEDIUM5.4ProjectPier 0.8.8 does not use the Secure flag for cookies
CVE-2013-3636MEDIUM5.4ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
CVE-2013-3635MEDIUM5.4ProjectPier 0.8.8 has stored XSS
CVE-2013-3629HIGH8.8ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
CVE-2013-3628HIGH8.8Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now