2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-10058 | HIGH | 8.6 | 3.1% | Aug 1, 2025 | An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) runnin... |
| CVE-2013-10057 | HIGH | 7.5 | 1.1% | Aug 1, 2025 | A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifical... |
| CVE-2013-10055 | CRITICAL | 9.3 | 1.3% | Aug 1, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in th... |
| CVE-2013-10053 | HIGH | 8.7 | 1.0% | Aug 1, 2025 | A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htacce... |
| CVE-2013-10051 | CRITICAL | 9.8 | 1.9% | Aug 1, 2025 | A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() withi... |
| CVE-2013-10050 | HIGH | 8.8 | 9.6% | Aug 1, 2025 | An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re... |
| CVE-2013-10049 | CRITICAL | 9.3 | 2.0% | Aug 1, 2025 | An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-... |
| CVE-2013-10048 | CRITICAL | 9.8 | 12.1% | Aug 1, 2025 | An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmw... |
| CVE-2013-10047 | CRITICAL | 9.3 | 1.0% | Aug 1, 2025 | An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote ... |
| CVE-2013-10046 | HIGH | 8.5 | 0.4% | Aug 1, 2025 | A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged u... |
| CVE-2013-10044 | HIGH | 8.8 | 1.3% | Aug 1, 2025 | An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to... |
| CVE-2013-10043 | CRITICAL | 9.5 | 2.0% | Jul 31, 2025 | A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the ... |
| CVE-2013-10042 | CRITICAL | 9.8 | 1.6% | Jul 31, 2025 | A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PAS... |
| CVE-2013-10040 | CRITICAL | 9.8 | 2.5% | Jul 31, 2025 | ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admi... |
| CVE-2013-10039 | HIGH | 8.7 | 3.4% | Jul 31, 2025 | A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to... |
| CVE-2013-10038 | CRITICAL | 9.3 | 1.6% | Jul 31, 2025 | An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The u... |
| CVE-2013-10037 | CRITICAL | 9.3 | 9.9% | Jul 31, 2025 | An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The para... |
| CVE-2013-10036 | HIGH | 8.4 | 0.4% | Jul 31, 2025 | A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing... |
| CVE-2013-10035 | HIGH | 8.7 | 1.4% | Jul 31, 2025 | A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin.... |
| CVE-2013-10034 | CRITICAL | 9.3 | 2.3% | Jul 31, 2025 | An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoi... |
| CVE-2013-10033 | CRITICAL | 9.3 | 1.2% | Jul 31, 2025 | An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw... |
| CVE-2013-10032 | HIGH | 8.8 | 2.5% | Jul 25, 2025 | An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php ... |
| CVE-2013-3307 | HIGH | 8.3 | 5.6% | Jul 11, 2025 | Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj... |
| CVE-2013-1440 | — | — | — | Jun 26, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2013-1424 | MEDIUM | 5.6 | 0.3% | Jun 26, 2025 | Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36c... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now