CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2015-0014

    Last Modified: 12 Apr 2025

    Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows Telnet Service Buffer Overflow Vulnerability."

    Published: 13 Jan 2015
    6.1
    Medium

    CVE-2015-0006

    Last Modified: 12 Apr 2025

    The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."

    Published: 13 Jan 2015
    7.2
    High

    CVE-2015-0002

    Last Modified: 12 Apr 2025

    The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or "Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability."

    Published: 13 Jan 2015
    7.8
    High

    CVE-2015-0015

    Last Modified: 12 Apr 2025

    Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."

    Published: 13 Jan 2015
    7.8
    High

    CVE-2015-0016

    Last Modified: 22 Apr 2026

    Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."

    Published: 13 Jan 2015
    1.9
    Low

    CVE-2015-0001

    Last Modified: 12 Apr 2025

    The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass the Protected Process Light protection mechanism and read the contents of arbitrary process-memory locations by leveraging administrative privileges, aka "Windows Error Reporting Security Feature Bypass Vulnerability."

    Published: 13 Jan 2015
    7.2
    High

    CVE-2015-0004

    Last Modified: 12 Apr 2025

    The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges by conducting a junction attack to load another user's UsrClass.dat registry hive, aka MSRC ID 20674 or "Microsoft User Profile Service Elevation of Privilege Vulnerability."

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100012

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100013

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100016

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the prod_id parameter.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100017

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the message field.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100023

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the quiz parameter to wp-admin/edit.php.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100038

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter to search/.

    Published: 13 Jan 2015
    6.5
    Medium

    CVE-2014-10032

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100018

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Unconfirmed plugin before 1.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in the unconfirmed page to wp-admin/network/users.php.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100019

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the LTree converter in Pomm before 1.1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-10031

    Last Modified: 12 Apr 2025

    Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100011

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100014

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a long string in a (1) 2001, (2) 2002, or (3) 2003 opcode to port 3000.

    Published: 13 Jan 2015
    6.4
    Medium

    CVE-2014-100015

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (dot dot) in the filename in a file upload.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100020

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100021

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in symfony/web/index.php/pim/viewEmployeeList in OrangeHRM before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the empsearch[employee_name][empId] parameter.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100022

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-admin/edit.php.

    Published: 13 Jan 2015
    6.8
    Medium

    CVE-2014-100025

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted request.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100026

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in readme.php in the April's Super Functions Pack plugin before 1.4.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100027

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100028

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted allows remote attackers to inject arbitrary web script or HTML via the username.

    Published: 13 Jan 2015
    5
    Medium

    CVE-2014-100029

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) newlang or (2) newtheme parameter.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100031

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) download.php or (2) main.php.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100032

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in top.html in the Airties Air 6372 modem allows remote attackers to inject arbitrary web script or HTML via the productboardtype parameter.

    Published: 13 Jan 2015
    5
    Medium

    CVE-2014-100033

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in LicensePal ArcticDesk before 1.2.5 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100034

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the frontend interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-100035

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the ticket grid in the admin interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100036

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in FlatPress 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter to the default URI.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100037

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to archives/.

    Published: 13 Jan 2015
    2.1
    Low

    CVE-2014-100039

    Last Modified: 12 Apr 2025

    mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third party information.

    Published: 13 Jan 2015
    6.5
    Medium

    CVE-2014-10034

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b) stores_paginate.php in admin/ajax/.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-10035

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEcho parameter to comments_paginate.php or (2) stores_paginate.php or the (3) affiliate_url, (4) description, (5) domain, (6) seo[description], (7) seo[heading], (8) seo[title], (9) seo[keywords], (10) setting[logo], (11) setting[perpage], or (12) setting[sitename] to admin/index.php.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-10036

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-10037

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the url parameter to photoalbum/index.php.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-10038

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100024

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Seo Panel before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-100030

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a ByEge action.

    Published: 13 Jan 2015
    6.5
    Medium

    CVE-2014-10033

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.

    Published: 13 Jan 2015
    8
    High

    CVE-2014-100005

    Last Modified: 22 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-10003

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-10009

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to the add_insurance_cat page; or (6) status[] parameter to the add_status page.

    Published: 13 Jan 2015
    4.3
    Medium

    CVE-2014-10016

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) unspecified vectors related to purchase_limit or the (2) name, (3) intl, (4) nocod, or (5) time parameter in an add_delivery_method action to wp-admin/admin-ajax.php.

    Published: 13 Jan 2015
    7.5
    High

    CVE-2014-10024

    Last Modified: 12 Apr 2025

    Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.

    Published: 13 Jan 2015
    6.8
    Medium

    CVE-2014-10027

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that (1) change the MAC filter restrict mode, (2) add a MAC address to the filter, or (3) remove a MAC address from the filter via a crafted request to index.cgi.

    Published: 13 Jan 2015