2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-6772MEDIUM4.3Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
CVE-2013-6358HIGH8.8PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then...
CVE-2013-4176MEDIUM5.5mysecureshell 1.31: Local Information Disclosure Vulnerability
CVE-2013-4175MEDIUM5.5MySecureShell 1.31 has a Local Denial of Service Vulnerability
CVE-2013-7185HIGH7.8PotPlayer 1.5.40688: .avi File Memory Corruption
CVE-2013-2773HIGH7.8Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
CVE-2013-6225CRITICAL9.8LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
CVE-2013-7380CRITICAL9.8The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
CVE-2013-6430MEDIUM5.4The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3....
CVE-2013-6231HIGH8.8SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
CVE-2013-5658MEDIUM6.1AultWare pwStore 2010.8.30.0 has XSS
CVE-2013-5657HIGH7.5AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
CVE-2013-5656HIGH7.8FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
CVE-2013-5638MEDIUM5.4Transcend WiFiSD 1.8 has persistent XSS
CVE-2013-5637MEDIUM5.4PQI AirCard has persistent XSS
CVE-2013-5571MEDIUM5.9HMailServer 5.3.x and prior: Memory Corruption which could cause DOS
CVE-2013-5122CRITICAL9.8Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthent...
CVE-2013-1642MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in QuiXplorer before 2.5.5 allow remote attackers to inject arbitrar...
CVE-2013-1420MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbit...
CVE-2013-0737MEDIUM6.1Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web scr...
CVE-2013-7351MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary w...
CVE-2013-3941CRITICAL9.8Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ mar...
CVE-2013-3939HIGH7.8xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows...
CVE-2013-3937HIGH7.8Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the...
CVE-2013-3932HIGH8.8SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated us...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now