2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3082Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote att...
CVE-2013-3081SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 ...
CVE-2013-2564Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a c...
CVE-2013-2563Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin passw...
CVE-2013-2562Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain...
CVE-2013-1973The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x befor...
CVE-2013-1756The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attacke...
CVE-2013-4728DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at...
CVE-2013-4727DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at...
CVE-2013-4725DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the...
CVE-2013-4724DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include...
CVE-2013-2602Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote...
CVE-2013-0250The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, w...
CVE-2013-4860Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote...
CVE-2013-3739Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read ...
CVE-2013-2618Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inj...
CVE-2013-2130ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted ...
CVE-2013-0733Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local user...
CVE-2013-0304ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to ...
CVE-2013-0302Unspecified vulnerability in ownCloud Server before 4.0.12 allows remote attackers to obtain sensitive information via u...
CVE-2013-1941The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time func...
CVE-2013-0204settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via...
CVE-2013-0191libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allo...
CVE-2013-7387Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v...
CVE-2013-7386Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2....

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now