CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-5446

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 4 Dec 2014
    7.5
    High

    CVE-2014-6035

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. (dot dot) in the FILENAME parameter.

    Published: 4 Dec 2014
    7
    High

    CVE-2014-9940

    Last Modified: 20 Apr 2025

    The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.

    Published: 4 Dec 2014
    4.6
    Medium

    CVE-2014-8106

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.

    Published: 4 Dec 2014
    4.3
    Medium

    CVE-2014-8122

    Last Modified: 12 Apr 2025

    Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.

    Published: 4 Dec 2014
    7.5
    High

    CVE-2014-9029

    Last Modified: 12 Apr 2025

    Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

    Published: 4 Dec 2014
    4.3
    Medium

    CVE-2014-9721

    Last Modified: 12 Apr 2025

    libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.

    Published: 4 Dec 2014
    7.5
    High

    CVE-2013-7416

    Last Modified: 12 Apr 2025

    canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.

    Published: 3 Dec 2014
    7.5
    High

    CVE-2014-9239

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter.

    Published: 3 Dec 2014
    7.5
    High

    CVE-2014-9240

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-9241

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to usercp.php, or (3) title parameter in the style-templates module in an edit_template action or (4) file parameter in the config-languages module in an edit action to admin/index.php.

    Published: 3 Dec 2014
    10
    Critical

    CVE-2014-9134

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Published: 3 Dec 2014
    5
    Medium

    CVE-2014-9234

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 3 Dec 2014
    6.5
    Medium

    CVE-2014-9235

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-9236

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.

    Published: 3 Dec 2014
    7.5
    High

    CVE-2014-9237

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request.

    Published: 3 Dec 2014
    5
    Medium

    CVE-2014-9238

    Last Modified: 12 Apr 2025

    D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.

    Published: 3 Dec 2014
    7.5
    High

    CVE-2014-9242

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-9243

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2) section_id parameter to edit_module_files.php, (3) news/add_post.php, (4) news/modify_group.php, (5) news/modify_post.php, or (6) news/modify_settings.php in wb/modules/.

    Published: 3 Dec 2014
    6.8
    Medium

    CVE-2014-8104

    Last Modified: 12 Apr 2025

    OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.

    Published: 3 Dec 2014
    6.8
    Medium

    CVE-2014-8771

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 3 Dec 2014
    3.5
    Low

    CVE-2014-8772

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticated users to inject arbitrary web script or HTML via the search parameter.

    Published: 3 Dec 2014
    6.8
    Medium

    CVE-2014-8773

    Last Modified: 12 Apr 2025

    MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-8774

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.

    Published: 3 Dec 2014
    5
    Medium

    CVE-2014-8775

    Last Modified: 12 Apr 2025

    MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 3 Dec 2014
    5
    Medium

    CVE-2014-9018

    Last Modified: 12 Apr 2025

    Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-3988

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file.

    Published: 3 Dec 2014
    7.2
    High

    CVE-2014-9141

    Last Modified: 12 Apr 2025

    The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.

    Published: 3 Dec 2014
    7.5
    High

    CVE-2014-9220

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.

    Published: 3 Dec 2014
    8.8
    High

    CVE-2014-0163

    Last Modified: 21 Nov 2024

    Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-8631

    Last Modified: 12 Apr 2025

    The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass intended DOM object restrictions via a call to an unspecified method.

    Published: 3 Dec 2014
    4.3
    Medium

    CVE-2014-8632

    Last Modified: 12 Apr 2025

    The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

    Published: 3 Dec 2014
    5
    Medium

    CVE-2014-9184

    Last Modified: 12 Apr 2025

    ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.

    Published: 2 Dec 2014
    10
    Critical

    CVE-2014-9183

    Last Modified: 12 Apr 2025

    ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.

    Published: 2 Dec 2014
    4.3
    Medium

    CVE-2014-9182

    Last Modified: 12 Apr 2025

    models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.

    Published: 2 Dec 2014
    6.5
    Medium

    CVE-2014-8789

    Last Modified: 12 Apr 2025

    GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not properly handled during extraction.

    Published: 2 Dec 2014
    5
    Medium

    CVE-2014-8874

    Last Modified: 12 Apr 2025

    The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remote attackers to obtain sensitive information via a direct request.

    Published: 2 Dec 2014
    4.3
    Medium

    CVE-2014-9174

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings.

    Published: 2 Dec 2014
    4
    Medium

    CVE-2014-8788

    Last Modified: 12 Apr 2025

    GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in an error message.

    Published: 2 Dec 2014
    7.2
    High

    CVE-2014-9113

    Last Modified: 12 Apr 2025

    CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.

    Published: 2 Dec 2014
    7.5
    High

    CVE-2014-9175

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.

    Published: 2 Dec 2014
    4.3
    Medium

    CVE-2014-9176

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php.

    Published: 2 Dec 2014
    7.5
    High

    CVE-2014-9178

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id parameter in the (2) download_project, (3) download_archive, or (4) remove_cat function.

    Published: 2 Dec 2014
    7.5
    High

    CVE-2014-8728

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System and FMS) 7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ranger_user[name] parameter.

    Published: 2 Dec 2014
    5.8
    Medium

    CVE-2014-8754

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the out parameter.

    Published: 2 Dec 2014
    7.5
    High

    CVE-2014-9173

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.

    Published: 2 Dec 2014
    5
    Medium

    CVE-2014-9177

    Last Modified: 12 Apr 2025

    The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php.

    Published: 2 Dec 2014
    4
    Medium

    CVE-2014-9179

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.

    Published: 2 Dec 2014
    5
    Medium

    CVE-2014-9180

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING.

    Published: 2 Dec 2014
    5
    Medium

    CVE-2014-9181

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/.

    Published: 2 Dec 2014