2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7480 | — | — | 0.9% | Aug 22, 2019 | The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. |
| CVE-2013-7479 | — | — | 0.9% | Aug 22, 2019 | The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. |
| CVE-2013-7478 | — | — | 0.9% | Aug 22, 2019 | The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. |
| CVE-2013-7477 | — | — | 0.9% | Aug 22, 2019 | The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. |
| CVE-2013-7476 | — | — | 0.7% | Aug 14, 2019 | The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. |
| CVE-2013-7475 | — | — | 0.9% | Aug 13, 2019 | The contact-form-plugin plugin before 3.52 for WordPress has XSS. |
| CVE-2013-7474 | — | — | 0.8% | Aug 1, 2019 | Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to... |
| CVE-2013-7473 | — | — | 0.6% | Aug 1, 2019 | Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account. |
| CVE-2013-7472 | — | — | 1.0% | Jun 15, 2019 | The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow paramete... |
| CVE-2013-1752 | — | — | — | Jun 3, 2019 | Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to ca... |
| CVE-2013-7470 | — | — | 2.5% | Apr 23, 2019 | cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allow... |
| CVE-2013-2805 | — | — | 3.9% | Mar 26, 2019 | Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,... |
| CVE-2013-2807 | — | — | 3.9% | Mar 26, 2019 | Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,... |
| CVE-2013-2806 | — | — | 3.9% | Mar 26, 2019 | Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,... |
| CVE-2013-7468 | — | — | 1.7% | Mar 7, 2019 | Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang di... |
| CVE-2013-7467 | — | — | 0.8% | Mar 7, 2019 | Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter. |
| CVE-2013-7466 | — | — | 4.1% | Mar 7, 2019 | Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ... |
| CVE-2013-7469 | — | — | 1.1% | Feb 21, 2019 | Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt ... |
| CVE-2013-5654 | — | — | 1.7% | Feb 15, 2019 | Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage |
| CVE-2013-2565 | — | — | 1.6% | Feb 15, 2019 | A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php d... |
| CVE-2013-2516 | — | — | 3.3% | Feb 15, 2019 | Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variabl... |
| CVE-2013-7465 | — | — | 3.3% | Oct 5, 2018 | Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote at... |
| CVE-2013-7203 | — | — | 0.4% | Sep 21, 2018 | gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to th... |
| CVE-2013-4451 | — | — | 3.1% | Sep 21, 2018 | gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writa... |
| CVE-2013-7464 | — | — | 0.8% | Aug 8, 2018 | In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now