2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-4498The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group gr...
CVE-2013-4489The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to exe...
CVE-2013-7382VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t...
CVE-2013-7379The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a s...
CVE-2013-4730Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE...
CVE-2013-1810Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticate...
CVE-2013-0197Cross-site scripting (XSS) vulnerability in the filter_draw_selection_area2 function in core/filter_api.php in MantisBT ...
CVE-2013-7376Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote...
CVE-2013-5939Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject ...
CVE-2013-5655Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote att...
CVE-2013-4471The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing p...
CVE-2013-4468VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut...
CVE-2013-4455Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying...
CVE-2013-3514Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read a...
CVE-2013-2700Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 f...
CVE-2013-2226Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands vi...
CVE-2013-2087Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary...
CVE-2013-2034Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1...
CVE-2013-1765Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote a...
CVE-2013-4562The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attacker...
CVE-2013-4552lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenti...
CVE-2013-4546The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to exec...
CVE-2013-4504The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted U...
CVE-2013-4503Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users ...
CVE-2013-4502The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file p...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now