2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5117 | — | — | 2.4% | Mar 12, 2014 | SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNu... |
| CVE-2013-4649 | — | — | 2.5% | Mar 12, 2014 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers t... |
| CVE-2013-3943 | — | — | 0.9% | Mar 12, 2014 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticat... |
| CVE-2013-1636 | — | — | 6.3% | Mar 12, 2014 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in ... |
| CVE-2013-5639 | — | — | 7.1% | Mar 11, 2014 | Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar... |
| CVE-2013-4467 | — | — | 32.8% | Mar 11, 2014 | Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40... |
| CVE-2013-4433 | — | — | 1.2% | Mar 11, 2014 | Cross-site scripting (XSS) vulnerability in XHProf before 0.9.4 allows remote attackers to inject arbitrary web script o... |
| CVE-2013-4413 | — | — | 2.9% | Mar 11, 2014 | Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allo... |
| CVE-2013-4198 | — | — | 1.1% | Mar 11, 2014 | mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated user... |
| CVE-2013-4199 | — | — | 1.1% | Mar 11, 2014 | (1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow r... |
| CVE-2013-4197 | — | — | 1.2% | Mar 11, 2014 | member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated us... |
| CVE-2013-4195 | — | — | 1.2% | Mar 11, 2014 | Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2... |
| CVE-2013-4196 | — | — | 1.4% | Mar 11, 2014 | The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.... |
| CVE-2013-4193 | — | — | 1.2% | Mar 11, 2014 | typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immu... |
| CVE-2013-4194 | — | — | 1.2% | Mar 11, 2014 | The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote ... |
| CVE-2013-4192 | — | — | 1.1% | Mar 11, 2014 | sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to sp... |
| CVE-2013-4191 | — | — | 1.2% | Mar 11, 2014 | zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restricti... |
| CVE-2013-4190 | — | — | 1.8% | Mar 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 t... |
| CVE-2013-4189 | — | — | 1.2% | Mar 11, 2014 | Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, ... |
| CVE-2013-4188 | — | — | 1.3% | Mar 11, 2014 | traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with adminis... |
| CVE-2013-3961 | — | — | 2.3% | Mar 11, 2014 | SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to exe... |
| CVE-2013-3928 | — | — | 37.1% | Mar 11, 2014 | Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote atta... |
| CVE-2013-2754 | — | — | 2.3% | Mar 11, 2014 | Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hij... |
| CVE-2013-2289 | — | — | 1.8% | Mar 11, 2014 | Cross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to injec... |
| CVE-2013-7334 | — | — | 0.9% | Mar 11, 2014 | Cross-site request forgery (CSRF) vulnerability in ImageCMS before 4.2 allows remote attackers to hijack the authenticat... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now