2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2013-10075CRITICAL9.1Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::...
CVE-2013-10070CRITICAL10PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names a...
CVE-2013-10069CRITICAL10The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an ...
CVE-2013-10068CRITICAL9.4Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based bu...
CVE-2013-10067CRITICAL9.4Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a...
CVE-2013-10066CRITICAL10An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an uplo...
CVE-2013-10064CRITICAL9.3A stack-based buffer overflow vulnerability exists in ActFax Server version 5.01. The server's RAW protocol interface fa...
CVE-2013-10054CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contai...
CVE-2013-10060CRITICAL9.4An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve...
CVE-2013-10055CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in th...
CVE-2013-10051CRITICAL9.3A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() withi...
CVE-2013-10049CRITICAL9.3An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-...
CVE-2013-10048CRITICAL9.3An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmw...
CVE-2013-10047CRITICAL9.3An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote ...
CVE-2013-10043CRITICAL9.5A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the ...
CVE-2013-10042CRITICAL9.3A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PAS...
CVE-2013-10040CRITICAL10ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admi...
CVE-2013-10038CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The u...
CVE-2013-10037CRITICAL9.3An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The para...
CVE-2013-10034CRITICAL9.3An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoi...
CVE-2013-10033CRITICAL9.3An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw...
CVE-2013-2513CRITICAL9.8The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded ...
CVE-2013-10023CRITICAL9.8A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affecte...
CVE-2013-10019CRITICAL9.8A vulnerability was found in OCLC-Research OAICat 1.5.61. It has been rated as critical. This issue affects some unknown...
CVE-2013-10018CRITICAL9.8A vulnerability was found in fanzila WebFinance 0.5. It has been declared as critical. Affected by this vulnerability is...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now