3.5
    Low

    CVE-2013-2299

    Last Modified: 8 Jan 2013

    Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Source:SecPod Research
    Published:22 Aug 2013
    6.1
    Medium

    CVE-2013-2294

    Last Modified: 19 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php or (3) Heads table in plates/summary.php.

    Source:Matthew R. Bucci
    Published:30 Jan 2020
    4.3
    Medium

    CVE-2013-2289

    Last Modified: 28 Sept 2015

    Cross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to admin/index.php.

    Source:Dognaedis
    Published:11 Mar 2014
    4.3
    Medium

    CVE-2013-2287

    Last Modified: 30 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

    Source:CodeV
    Published:4 Apr 2014
    7.6
    High

    CVE-2013-2271

    Last Modified: 4 Mar 2013

    The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and gain administrator access via a request to login.cgi.

    Source:Ivano Binetti
    Published:15 Nov 2013
    7.2
    High

    CVE-2013-2267

    Last Modified: 8 Oct 2015

    PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.

    Source:High-Tech Bridge
    Published:27 Jan 2020
    7.5
    High

    CVE-2013-2261

    Last Modified: 5 Nov 2015

    Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure

    Source:Mario Heiderich
    Published:4 Nov 2019
    9.8
    Critical

    CVE-2013-2251

    Last Modified: 27 Jul 2013

    Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

    Source:Metasploit
    Published:14 Jul 2013
    5.8
    Medium

    CVE-2013-2248

    Last Modified: 25 Oct 2017

    Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

    Source:Takeshi Terada
    Published:14 Jul 2013
    7.5
    High

    CVE-2013-2227

    Last Modified: 21 Jun 2013

    GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

    Source:LiquidWorm
    Published:1 Nov 2019
    7.5
    High

    CVE-2013-2226

    Last Modified: 21 Jun 2013

    Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

    Source:LiquidWorm
    Published:14 May 2014
    6.4
    Medium

    CVE-2013-2225

    Last Modified: 12 Nov 2016

    inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.

    Source:Xavier Mehrenberger
    Published:27 May 2014
    5
    Medium

    CVE-2013-2218

    Last Modified: 5 Nov 2015

    Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.

    Source:Daniel P. Berrange
    Published:1 Jul 2013
    1.2
    Low

    CVE-2013-2217

    Last Modified: 11 Apr 2025

    cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

    Published:27 Jun 2013
    7.5
    High

    CVE-2013-2186

    Last Modified: 11 Apr 2025

    The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

    Published:15 Oct 2013
    5.8
    Medium

    CVE-2013-2182

    Last Modified: 31 Oct 2015

    The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash.

    Source:felipensp
    Published:13 Jun 2014
    4.3
    Medium

    CVE-2013-2172

    Last Modified: 11 Apr 2025

    jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."

    Published:25 Jun 2013
    6.9
    Medium

    CVE-2013-2171

    Last Modified: 26 Jun 2013

    The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass filesystem write permissions and consequently gain privileges via a crafted application that leverages read permissions, and makes mmap and ptrace system calls.

    Source:Metasploit
    Published:2 Jul 2013
    7.5
    High

    CVE-2013-2165

    Last Modified: 11 Apr 2025

    ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

    Published:10 Jul 2013
    5
    Medium

    CVE-2013-2160

    Last Modified: 9 Jul 2013

    The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.

    Source:SEC Consult
    Published:26 Jun 2013
    6.5
    Medium

    CVE-2013-2143

    Last Modified: 26 Mar 2014

    The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

    Source:Metasploit
    Published:24 Mar 2014
    9.3
    Critical

    CVE-2013-2134

    Last Modified: 28 Oct 2015

    Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.

    Source:Jon Passki
    Published:5 Jun 2013
    5
    Medium

    CVE-2013-2131

    Last Modified: 15 Nov 2017

    Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.

    Source:Thomas Pollet
    Published:18 Apr 2013
    6
    Medium

    CVE-2013-2121

    Last Modified: 23 Jul 2013

    Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

    Source:Metasploit
    Published:7 Jun 2013
    7.5
    High

    CVE-2013-2118

    Last Modified: 21 May 2014

    SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.

    Source:Gregory Draperi
    Published:9 Jul 2013
    8.1
    High

    CVE-2013-2115

    Last Modified: 5 Jun 2013

    Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.

    Source:Metasploit
    Published:22 May 2013
    6
    Medium

    CVE-2013-2113

    Last Modified: 22 Aug 2013

    The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.

    Source:Metasploit
    Published:7 Jun 2013
    5.4
    Medium

    CVE-2013-2108

    Last Modified: 23 Oct 2015

    WordPress WP Cleanfix Plugin 2.4.4 has CSRF

    Source:Enigma Ideas
    Published:10 Feb 2020
    6.8
    Medium

    CVE-2013-2107

    Last Modified: 23 Oct 2015

    Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the mailonupdate_mailto parameter in the mail-on-update page to wp-admin/options-general.php. NOTE: a third party claims that 5.2.1 and 5.2.2 are also vulnerable, but the issue might require a separate CVE identifier since this might reflect an incomplete fix.

    Source:Henri Salo
    Published:23 May 2014
    7.8
    High

    CVE-2013-2097

    Last Modified: 24 Oct 2015

    ZPanel through 10.1.0 has Remote Command Execution

    Source:Metasploit
    Published:12 Feb 2020
    8.4
    High

    CVE-2013-2094

    Last Modified: 3 May 2018

    The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

    Source:sd
    Published:14 May 2013
    7.1
    High

    CVE-2013-2088

    Last Modified: 12 Oct 2016

    contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

    Source:GlacierZ0ne
    Published:31 May 2013
    7.4
    High

    CVE-2013-2072

    Last Modified: 11 Apr 2025

    Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.

    Published:17 May 2013
    9.4
    Critical

    CVE-2013-2068

    Last Modified: 24 Dec 2013

    Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.

    Source:Metasploit
    Published:4 Sept 2013
    7.5
    High

    CVE-2013-2028

    Last Modified: 17 May 2013

    The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

    Source:Mert SARICA
    Published:18 Jul 2013
    9.8
    Critical

    CVE-2013-2010

    Last Modified: 1 May 2013

    WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

    Source:Metasploit
    Published:12 Feb 2020
    8.8
    High

    CVE-2013-2009

    Last Modified: 19 Oct 2015

    WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution

    Source:anonymous
    Published:7 Feb 2020
    2.1
    Low

    CVE-2013-2006

    Last Modified: 11 Apr 2025

    OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.

    Published:19 Apr 2013
    9.3
    Critical

    CVE-2013-1966

    Last Modified: 5 Jun 2013

    Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.

    Source:Metasploit
    Published:22 May 2013
    9.3
    Critical

    CVE-2013-1965

    Last Modified: 11 Apr 2025

    Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

    Published:22 May 2013
    3.7
    Low

    CVE-2013-1959

    Last Modified: 14 May 2013

    kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.

    Source:Andrew Lutomirski
    Published:3 May 2013
    4.3
    Medium

    CVE-2013-1950

    Last Modified: 16 Jul 2013

    The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.

    Source:Sean Verity
    Published:18 Apr 2013
    4.3
    Medium

    CVE-2013-1942

    Last Modified: 15 Oct 2015

    Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.

    Source:Malte Batram
    Published:15 Aug 2013
    6.1
    Medium

    CVE-2013-1938

    Last Modified: 10 Oct 2015

    Zimbra 2013 has XSS in aspell.php

    Source:Michael Scherer
    Published:12 Feb 2020
    6.1
    Medium

    CVE-2013-1937

    Last Modified: 10 Oct 2015

    Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a third party reports that this is "not exploitable.

    Source:waraxe
    Published:16 Apr 2013
    8.8
    High

    CVE-2013-1916

    Last Modified: 17 Feb 2011

    In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

    Source:ADVtools
    Published:24 Jun 2022
    6
    Medium

    CVE-2013-1892

    Last Modified: 8 Apr 2013

    MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

    Source:Metasploit
    Published:24 Mar 2013
    6.5
    Medium

    CVE-2013-1891

    Last Modified: 22 Nov 2016

    In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.

    Source:waraxe
    Published:24 Jun 2022
    5
    Medium

    CVE-2013-1884

    Last Modified: 8 Oct 2015

    The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.

    Source:Greg McMullin
    Published:4 Apr 2013
    9.3
    Critical

    CVE-2013-1868

    Last Modified: 14 Jul 2017

    Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.

    Source:coolkaveh
    Published:10 Jul 2013