2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4595——The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used ins...
CVE-2013-3082——Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote att...
CVE-2013-3081——SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 ...
CVE-2013-2564——Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a c...
CVE-2013-2563——Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin passw...
CVE-2013-2562——Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain...
CVE-2013-1973——The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x befor...
CVE-2013-1756——The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attacke...
CVE-2013-4728——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at...
CVE-2013-4727——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at...
CVE-2013-4725——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the...
CVE-2013-4724——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include...
CVE-2013-2602——Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote...
CVE-2013-0250——The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, w...
CVE-2013-4860——Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote...
CVE-2013-3739——Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read ...
CVE-2013-2618——Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inj...
CVE-2013-2130——ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted ...
CVE-2013-0733——Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local user...
CVE-2013-0304——ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to ...
CVE-2013-0302——Unspecified vulnerability in ownCloud Server before 4.0.12 allows remote attackers to obtain sensitive information via u...
CVE-2013-1941——The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time func...
CVE-2013-0204——settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via...
CVE-2013-0191——libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allo...
CVE-2013-7387——Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now