2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-2602Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote...
CVE-2013-0250The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, w...
CVE-2013-4860Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote...
CVE-2013-3739Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read ...
CVE-2013-2618Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inj...
CVE-2013-2130ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted ...
CVE-2013-0733Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local user...
CVE-2013-0304ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to ...
CVE-2013-0302Unspecified vulnerability in ownCloud Server before 4.0.12 allows remote attackers to obtain sensitive information via u...
CVE-2013-1941The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time func...
CVE-2013-0204settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via...
CVE-2013-0191libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allo...
CVE-2013-7387Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v...
CVE-2013-7386Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2....
CVE-2013-6470The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Re...
CVE-2013-6433The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configurati...
CVE-2013-4596The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote a...
CVE-2013-3476Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows ...
CVE-2013-3258Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attacker...
CVE-2013-3257Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote att...
CVE-2013-2710Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows...
CVE-2013-2298Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a cr...
CVE-2013-2019Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple...
CVE-2013-2014OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and...
CVE-2013-1818maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now