2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-10059HIGH7.2An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa...
CVE-2013-10058HIGH8.6An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) runnin...
CVE-2013-10057HIGH7.5A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifical...
CVE-2013-10055CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in th...
CVE-2013-10053HIGH8.7A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htacce...
CVE-2013-10051CRITICAL9.8A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() withi...
CVE-2013-10050HIGH8.8An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re...
CVE-2013-10049CRITICAL9.3An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-...
CVE-2013-10048CRITICAL9.8An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmw...
CVE-2013-10047CRITICAL9.3An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote ...
CVE-2013-10046HIGH8.5A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged u...
CVE-2013-10044HIGH8.8An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to...
CVE-2013-10043CRITICAL9.5A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the ...
CVE-2013-10042CRITICAL9.8A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PAS...
CVE-2013-10040CRITICAL9.8ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admi...
CVE-2013-10039HIGH8.7A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to...
CVE-2013-10038CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The u...
CVE-2013-10037CRITICAL9.3An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The para...
CVE-2013-10036HIGH8.4A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing...
CVE-2013-10035HIGH8.7A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin....
CVE-2013-10034CRITICAL9.3An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoi...
CVE-2013-10033CRITICAL9.3An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw...
CVE-2013-10032HIGH8.8An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php ...
CVE-2013-3307HIGH8.3Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj...
CVE-2013-1440——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now