2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-4406——The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not pro...
CVE-2013-4498——The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group gr...
CVE-2013-4489——The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to exe...
CVE-2013-7382——VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t...
CVE-2013-7379——The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a s...
CVE-2013-4730——Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE...
CVE-2013-1810——Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticate...
CVE-2013-0197——Cross-site scripting (XSS) vulnerability in the filter_draw_selection_area2 function in core/filter_api.php in MantisBT ...
CVE-2013-7376——Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote...
CVE-2013-5939——Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject ...
CVE-2013-5655——Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote att...
CVE-2013-4471——The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing p...
CVE-2013-4468——VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut...
CVE-2013-4455——Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying...
CVE-2013-3514——Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read a...
CVE-2013-2700——Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 f...
CVE-2013-2226——Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands vi...
CVE-2013-2087——Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary...
CVE-2013-2034——Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1...
CVE-2013-1765——Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote a...
CVE-2013-4562——The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attacker...
CVE-2013-4552——lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenti...
CVE-2013-4546——The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to exec...
CVE-2013-4504——The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted U...
CVE-2013-4503——Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now