2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2013-20006HIGH8.7Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST ...
CVE-2013-10031HIGH7.5Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
CVE-2013-10073HIGH8.8Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-co...
CVE-2013-10065HIGH7.5A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH ...
CVE-2013-10052HIGH8.5ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks....
CVE-2013-10061HIGH7.2An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver...
CVE-2013-10060HIGH7.2An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve...
CVE-2013-10059HIGH7.2An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa...
CVE-2013-10058HIGH8.6An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) runnin...
CVE-2013-10057HIGH7.5A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifical...
CVE-2013-10053HIGH8.7A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htacce...
CVE-2013-10050HIGH8.8An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re...
CVE-2013-10046HIGH8.5A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged u...
CVE-2013-10044HIGH8.8An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to...
CVE-2013-10039HIGH8.7A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to...
CVE-2013-10036HIGH8.4A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing...
CVE-2013-10035HIGH8.7A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin....
CVE-2013-10032HIGH8.8An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php ...
CVE-2013-3307HIGH8.3Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj...
CVE-2013-10030HIGH7.5A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Af...
CVE-2013-10029HIGH8.8A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vu...
CVE-2013-10027HIGH8.8A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affe...
CVE-2013-10025HIGH8.8A vulnerability was found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this issu...
CVE-2013-10024HIGH7.5A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this...
CVE-2013-10007HIGH7.5A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unkn...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now