2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-10058HIGH8.6An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) runnin...
CVE-2013-10057HIGH7.5A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifical...
CVE-2013-10055CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in th...
CVE-2013-10053HIGH8.7A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htacce...
CVE-2013-10051CRITICAL9.8A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() withi...
CVE-2013-10050HIGH8.8An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re...
CVE-2013-10049CRITICAL9.3An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-...
CVE-2013-10048CRITICAL9.8An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmw...
CVE-2013-10047CRITICAL9.3An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote ...
CVE-2013-10046HIGH8.5A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged u...
CVE-2013-10044HIGH8.8An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to...
CVE-2013-10043CRITICAL9.5A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the ...
CVE-2013-10042CRITICAL9.8A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PAS...
CVE-2013-10040CRITICAL9.8ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admi...
CVE-2013-10039HIGH8.7A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to...
CVE-2013-10038CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The u...
CVE-2013-10037CRITICAL9.3An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The para...
CVE-2013-10036HIGH8.4A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing...
CVE-2013-10035HIGH8.7A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin....
CVE-2013-10034CRITICAL9.3An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoi...
CVE-2013-10033CRITICAL9.3An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw...
CVE-2013-10032HIGH8.8An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php ...
CVE-2013-3307HIGH8.3Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj...
CVE-2013-1440Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2013-1424MEDIUM5.6Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36c...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now