2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7482——The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
CVE-2013-7481——The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
CVE-2013-7480——The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
CVE-2013-7479——The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
CVE-2013-7478——The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
CVE-2013-7477——The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
CVE-2013-7476——The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
CVE-2013-7475——The contact-form-plugin plugin before 3.52 for WordPress has XSS.
CVE-2013-7474——Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to...
CVE-2013-7473——Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
CVE-2013-7472——The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow paramete...
CVE-2013-7471CRITICAL9.8An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-6...
CVE-2013-1752——Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to ca...
CVE-2013-7285CRITICAL9.8Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem...
CVE-2013-7470——cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allow...
CVE-2013-2805——Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,...
CVE-2013-2807——Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,...
CVE-2013-2806——Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,...
CVE-2013-7468——Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang di...
CVE-2013-7467——Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
CVE-2013-7466——Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ...
CVE-2013-7469——Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt ...
CVE-2013-5654——Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage
CVE-2013-2565——A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php d...
CVE-2013-2516——Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variabl...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now