2013 — CVEs disclosed (Default sort: published descending; newest first.)

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Showing 4160 of 6830 results
«« First « Prev Page 3 / 342 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2013-10038 An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in arbitrary code execution as the web server user. 9.3 1.28% 2025-07-31 2026-06-16
CVE-2013-10037 An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges. 9.3 9.62% 2025-07-31 2026-06-16
CVE-2013-10036 A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing the UserName parameter in the NetConfig.ini configuration file. A crafted .ini file containing an overly long UserName value can overwrite the Structured Exception Handler (SEH), leading to arbitrary code execution when the application processes the file. 8.4 0.41% 2025-07-31 2026-06-16
CVE-2013-10035 A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin. An authenticated user can execute arbitrary PHP code via multiple endpoints, including appFolderAjax.php, casesStartPage_Ajax.php, and cases_SchedulerGetPlugins.php, by supplying crafted POST requests to parameters such as action and params. These endpoints fail to validate user input and directly invoke PHP functions like system() with user-supplied parameters, enabling remot 8.7 1.46% 2025-07-31 2026-06-16
CVE-2013-10034 An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST request. Due to the lack of authentication and input sanitation, an attacker can upload a file with an .asp extension to a web-accessible directory, which can then be invoked to execute arbitrary code with the privileges of the IUSR account. The vuln 9.3 1.84% 2025-07-31 2026-06-16
CVE-2013-10033 An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental conditions. This can lead to remote code execution by writing a PHP payload to the web-accessible temporary directory. The vulnerability has been confirmed in versions including 0.9.2.beta, 0.9.2.1294.beta, and 0.9.2.1306-3. 9.3 1.26% 2025-07-31 2026-06-16
CVE-2013-10032 An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. By uploading a .pht file containing PHP code, an attacker can bypass blacklist-based restrictions and place executable code within the web root. A crafted request using a polyglot or disguised extension allows the attacker to execute the payload by accessing the 8.7 2.48% 2025-07-25 2026-06-16
CVE-2013-3307 Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000. 8.3 5.62% 2025-07-11 2026-06-16
CVE-2013-1440 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A 2025-06-26 2025-06-26
CVE-2013-1424 Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787. 5.6 0.31% 2025-06-26 2026-06-16
CVE-2013-2513 The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file. 9.8 1.69% 2023-12-12 2026-06-16
CVE-2013-5299 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5298 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5297 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5296 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5295 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5294 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5293 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5292 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
CVE-2013-5291 Rejected reason: This candidate is unused by its CNA. N/A 0.04% 2023-09-14 2023-11-06
«« First « Prev Page 3 / 342 Next »
cvelogic Threat Intelligence