7.5
    High

    CVE-2013-3530

    Last Modified: 10 Oct 2015

    SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter.

    Source:Ashiyane Digital Security Team
    Published:10 May 2013
    4.3
    Medium

    CVE-2013-3529

    Last Modified: 2 Apr 2013

    Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message parameter.

    Source:Rob Armstrong
    Published:10 May 2013
    7.5
    High

    CVE-2013-3528

    Last Modified: 8 Nov 2013

    Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."

    Source:EgiX
    Published:10 May 2013
    7.5
    High

    CVE-2013-3527

    Last Modified: 8 Apr 2013

    Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.

    Source:bl4ckw0rm
    Published:10 May 2013
    4.3
    Medium

    CVE-2013-3526

    Last Modified: 10 Oct 2015

    Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter.

    Source:Beni_Vanda
    Published:10 May 2013
    7.5
    High

    CVE-2013-3525

    Last Modified: 15 Oct 2015

    SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.

    Source:cheki
    Published:10 May 2013
    7.5
    High

    CVE-2013-3524

    Last Modified: 16 Apr 2013

    SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally reported as a problem in phpVMS.

    Source:NoGe
    Published:10 May 2013
    6.5
    Medium

    CVE-2013-3522

    Last Modified: 6 Mar 2014

    SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.

    Source:Metasploit
    Published:10 May 2013
    7.5
    High

    CVE-2013-3520

    Last Modified: 23 Jul 2013

    VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Metasploit
    Published:17 Jun 2013
    4.3
    Medium

    CVE-2013-3515

    Last Modified: 5 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) package parameter to www/admin/plugin-index.php or the (2) group parameter to www/admin/plugin-settings.php.

    Source:High-Tech Bridge SA
    Published:29 Jul 2013
    4.3
    Medium

    CVE-2013-3514

    Last Modified: 5 Jul 2013

    Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to read arbitrary files.

    Source:High-Tech Bridge SA
    Published:14 May 2014
    6.5
    Medium

    CVE-2013-3502

    Last Modified: 25 Apr 2013

    monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by leveraging a JOSSO SSO cookie.

    Source:Metasploit
    Published:8 May 2013
    9.3
    Critical

    CVE-2013-3482

    Last Modified: 9 Jul 2013

    Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS file.

    Source:Metasploit
    Published:19 Jan 2014
    7.8
    High

    CVE-2013-3431

    Last Modified: 15 Mar 2013

    Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.

    Source:Bassem
    Published:25 Jul 2013
    9
    Critical

    CVE-2013-3430

    Last Modified: 15 Mar 2013

    Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.

    Source:Bassem
    Published:25 Jul 2013
    7.8
    High

    CVE-2013-3429

    Last Modified: 15 Mar 2013

    Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163.

    Source:Bassem
    Published:25 Jul 2013
    8.5
    High

    CVE-2013-3365

    Last Modified: 28 Jul 2013

    TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote port to adm/management.asp; (3) pptp username, (4) pptp password, (5) ip, (6) gateway, (7) l2tp username, or (8) l2tp password to internet/wan.asp; (9) NtpDstStart, (10) NtpDstEnd, or (11) NtpDstOffset to adm/time.asp; or (12) device url to adm/management.asp. NOTE: vectors 9, 10, and 11 can be exploited by unauthenticated remote attackers by leveraging CVE-2013-3098.

    Source:Jacob Holcomb
    Published:4 Feb 2014
    8.8
    High

    CVE-2013-3346

    Last Modified: 17 Dec 2013

    Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

    Source:Metasploit
    Published:14 May 2013
    5
    Medium

    CVE-2013-3336

    Last Modified: 8 May 2013

    Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.

    Source:HTP
    Published:9 May 2013
    6.1
    Medium

    CVE-2013-3320

    Last Modified: 22 Oct 2015

    Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.

    Source:M. Heinzl
    Published:29 Jan 2020
    5
    Medium

    CVE-2013-3319

    Last Modified: 11 Apr 2025

    The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.

    Published:16 Aug 2013
    7.5
    High

    CVE-2013-3314

    Last Modified: 26 Aug 2013

    The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.

    Source:Craig Young
    Published:21 Nov 2019
    8.3
    High

    CVE-2013-3307

    Last Modified: 24 Jun 2013

    Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.

    Source:m-1-k-3
    Published:11 Jul 2025
    5
    Medium

    CVE-2013-3304

    Last Modified: 25 Oct 2014

    Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

    Source:XLabs Security
    Published:30 Oct 2014
    7.2
    High

    CVE-2013-3301

    Last Modified: 15 Oct 2015

    The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.

    Source:anonymous
    Published:11 Apr 2013
    4.3
    Medium

    CVE-2013-3299

    Last Modified: 5 Nov 2015

    RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string.

    Source:Akshaysinh Vaghela
    Published:6 Jul 2013
    7.5
    High

    CVE-2013-3294

    Last Modified: 17 May 2013

    Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.

    Source:High-Tech Bridge SA
    Published:11 Feb 2014
    9.3
    Critical

    CVE-2013-3248

    Last Modified: 13 Jul 2013

    Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.

    Source:Metasploit
    Published:3 Oct 2013
    5.5
    Medium

    CVE-2013-3242

    Last Modified: 1 Nov 2016

    plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors.

    Source:EgiX
    Published:3 May 2013
    4
    Medium

    CVE-2013-3241

    Last Modified: 1 May 2013

    export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request.

    Source:waraxe
    Published:26 Apr 2013
    6.5
    Medium

    CVE-2013-3240

    Last Modified: 1 May 2013

    Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a parameter that specifies a crafted export type.

    Source:waraxe
    Published:26 Apr 2013
    4.6
    Medium

    CVE-2013-3239

    Last Modified: 1 May 2013

    phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.

    Source:waraxe
    Published:26 Apr 2013
    6
    Medium

    CVE-2013-3238

    Last Modified: 1 May 2013

    phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.

    Source:Metasploit
    Published:26 Apr 2013
    9.8
    Critical

    CVE-2013-3215

    Last Modified: 4 Oct 2017

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

    Source:EgiX
    Published:29 Jan 2020
    9.8
    Critical

    CVE-2013-3214

    Last Modified: 4 Oct 2017

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    Source:Metasploit
    Published:28 Jan 2020
    7.5
    High

    CVE-2013-3213

    Last Modified: 4 Oct 2017

    Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to soap/customerportal.php, or (3) emailaddress parameter in the SearchContactsByEmail method to soap/vtigerolservice.php; or remote authenticated users to execute arbitrary SQL commands via the (4) emailaddress parameter in the SearchContactsByEmail method to soap/thunderbirdplugin.php.

    Source:EgiX
    Published:2 Apr 2014
    8.1
    High

    CVE-2013-3212

    Last Modified: 4 Oct 2017

    vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.

    Source:EgiX
    Published:28 Jan 2020
    9.3
    Critical

    CVE-2013-3205

    Last Modified: 23 Sept 2013

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Metasploit
    Published:11 Sept 2013
    9.3
    Critical

    CVE-2013-3184

    Last Modified: 4 Sept 2013

    Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Metasploit
    Published:14 Aug 2013
    4.3
    Medium

    CVE-2013-3179

    Last Modified: 12 Sept 2013

    Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."

    Source:Vulnerability-Lab
    Published:11 Sept 2013
    9.3
    Critical

    CVE-2013-3174

    Last Modified: 23 Jul 2013

    DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."

    Source:Andrés Gómez Ramírez
    Published:10 Jul 2013
    4.3
    Medium

    CVE-2013-3166

    Last Modified: 10 Sept 2013

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via vectors involving incorrect auto-selection of the Shift JIS encoding, leading to cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability," a different vulnerability than CVE-2013-0015.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3164

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Metasploit
    Published:10 Jul 2013
    8.8
    High

    CVE-2013-3163

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3162

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3115.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3161

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3153

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3148.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3152

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3146.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3151

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3163.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3150

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3145.

    Source:Metasploit
    Published:10 Jul 2013