2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-7481——The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
CVE-2013-7480——The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
CVE-2013-7479——The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
CVE-2013-7478——The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
CVE-2013-7477——The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
CVE-2013-7476——The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
CVE-2013-7475——The contact-form-plugin plugin before 3.52 for WordPress has XSS.
CVE-2013-7474——Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to...
CVE-2013-7473——Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
CVE-2013-7472——The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow paramete...
CVE-2013-1752——Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to ca...
CVE-2013-7470——cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allow...
CVE-2013-2805——Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,...
CVE-2013-2807——Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,...
CVE-2013-2806——Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5,...
CVE-2013-7468——Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang di...
CVE-2013-7467——Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
CVE-2013-7466——Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ...
CVE-2013-7469——Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt ...
CVE-2013-5654——Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage
CVE-2013-2565——A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php d...
CVE-2013-2516——Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variabl...
CVE-2013-7465——Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote at...
CVE-2013-7203——gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to th...
CVE-2013-4451——gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writa...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now