2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-7417Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote ...
CVE-2013-3295Directory traversal vulnerability in install/popup.php in Exponent CMS before 2.2.0 RC1 allows remote attackers to inclu...
CVE-2013-4663git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary comman...
CVE-2013-6998Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6870. Reason: This candidate is a duplicate of...
CVE-2013-6919The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote ...
CVE-2013-6241The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, ...
CVE-2013-6227Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly ...
CVE-2013-6043The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attem...
CVE-2013-6041index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharact...
CVE-2013-5958The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 a...
CVE-2013-4793The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS ...
CVE-2013-4769The cloud controller (aka CLC) component in Eucalyptus 3.3.x and 3.4.x before 3.4.2, when the dns.recursive.enabled sett...
CVE-2013-4754Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users ...
CVE-2013-4753Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to ...
CVE-2013-7401The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via...
CVE-2013-4442Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which ma...
CVE-2013-4440Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent...
CVE-2013-7402Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (c...
CVE-2013-6435Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose ...
CVE-2013-4399The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identi...
CVE-2013-2810Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC...
CVE-2013-7416canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell ...
CVE-2013-6494fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows ...
CVE-2013-6497clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as ...
CVE-2013-3678Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to g...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now