CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2014-2226

    Last Modified: 12 Apr 2025

    Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

    Published: 29 Jul 2014
    6.8
    Medium

    CVE-2014-4909

    Last Modified: 12 Apr 2025

    Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-4710

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the Full Name field.

    Published: 29 Jul 2014
    7.5
    High

    CVE-2014-5114

    Last Modified: 12 Apr 2025

    WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.

    Published: 29 Jul 2014
    5
    Medium

    CVE-2014-5115

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile parameter to index.php.

    Published: 29 Jul 2014
    3.5
    Low

    CVE-2014-3551

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.

    Published: 29 Jul 2014
    4.9
    Medium

    CVE-2014-3553

    Last Modified: 12 Apr 2025

    mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships.

    Published: 29 Jul 2014
    7.5
    High

    CVE-2014-3541

    Last Modified: 12 Apr 2025

    The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-3542

    Last Modified: 12 Apr 2025

    mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-3543

    Last Modified: 12 Apr 2025

    mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via a package with a manifest file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue affecting IMSCP resources and the IMSCC format.

    Published: 29 Jul 2014
    3.5
    Low

    CVE-2014-3544

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.

    Published: 29 Jul 2014
    6
    Medium

    CVE-2014-3552

    Last Modified: 12 Apr 2025

    The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

    Published: 29 Jul 2014
    6
    Medium

    CVE-2014-3545

    Last Modified: 12 Apr 2025

    Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execute arbitrary code via a calculated question in a quiz.

    Published: 29 Jul 2014
    5
    Medium

    CVE-2014-3546

    Last Modified: 12 Apr 2025

    Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-3547

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in badges/renderer.php in Moodle 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via an external badge.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-3548

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger an AJAX exception dialog.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-3549

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

    Published: 29 Jul 2014
    4.3
    Medium

    CVE-2014-3550

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted (1) error or (2) success message for a scheduled task.

    Published: 29 Jul 2014
    6.8
    Medium

    CVE-2014-3554

    Last Modified: 12 Apr 2025

    Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

    Published: 29 Jul 2014
    4
    Medium

    CVE-2014-3303

    Last Modified: 12 Apr 2025

    The web framework in Cisco WebEx Meetings Server does not properly restrict the content of query strings, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuj81713.

    Published: 28 Jul 2014
    6.8
    Medium

    CVE-2014-2974

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

    Published: 28 Jul 2014
    4.3
    Medium

    CVE-2014-2975

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

    Published: 28 Jul 2014
    7.8
    High

    CVE-2013-4840

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 28 Jul 2014
    5
    Medium

    CVE-2014-3304

    Last Modified: 12 Apr 2025

    The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the returned messages, aka Bug ID CSCuj81722.

    Published: 28 Jul 2014
    5
    Medium

    CVE-2014-5107

    Last Modified: 12 Apr 2025

    concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php, or (16) files/search.php in single_pages/dashboard/.

    Published: 28 Jul 2014
    4.3
    Medium

    CVE-2014-5108

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.

    Published: 28 Jul 2014
    4.3
    Medium

    CVE-2014-5110

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HTML via the id_nodo parameter.

    Published: 28 Jul 2014
    7.5
    High

    CVE-2014-5104

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) affiliate_banner_id parameter to affiliate_show_banner.php, (3) country parameter in a process action to create_account.php, or (4) entry_country_id parameter in an edit action to admin/create_account.php.

    Published: 28 Jul 2014
    4.3
    Medium

    CVE-2014-5105

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) a_country parameter in a process action to affiliate_signup.php or (2) entry_country_id parameter in an edit action to admin/create_account.php.

    Published: 28 Jul 2014
    4.3
    Medium

    CVE-2014-5106

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to admin/install/index.php.

    Published: 28 Jul 2014
    7.5
    High

    CVE-2014-5109

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.

    Published: 28 Jul 2014
    5
    Medium

    CVE-2014-5111

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.

    Published: 28 Jul 2014
    7.5
    High

    CVE-2014-5112

    Last Modified: 12 Apr 2025

    maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.

    Published: 28 Jul 2014
    4.3
    Medium

    CVE-2014-5113

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in test.php in Visualware MyConnection Server 9.7i allow remote attackers to inject arbitrary web script or HTML via the (1) testtype, (2) ver, (3) cm, (4) map, (5) lines, (6) pps, (7) bpp, (8) codec, (9) provtext, (10) provtextextra, (11) provlink, or (12) duration parameter.

    Published: 28 Jul 2014
    4.9
    Medium

    CVE-2014-5253

    Last Modified: 12 Apr 2025

    OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

    Published: 28 Jul 2014
    7.5
    High

    CVE-2014-4725

    Last Modified: 12 Apr 2025

    The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

    Published: 27 Jul 2014
    7.5
    High

    CVE-2014-4726

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.

    Published: 27 Jul 2014
    4.3
    Medium

    CVE-2014-4748

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 26 Jul 2014
    5
    Medium

    CVE-2014-2966

    Last Modified: 12 Apr 2025

    The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.

    Published: 26 Jul 2014
    8.5
    High

    CVE-2014-2625

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to read arbitrary files via crafted input, aka ZDI-CAN-2023.

    Published: 26 Jul 2014
    9.4
    Critical

    CVE-2014-2626

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.

    Published: 26 Jul 2014
    2.1
    Low

    CVE-2014-4747

    Last Modified: 12 Apr 2025

    The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.

    Published: 26 Jul 2014
    4.3
    Medium

    CVE-2014-4857

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.

    Published: 26 Jul 2014
    7.2
    High

    CVE-2014-4971

    Last Modified: 12 Apr 2025

    Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

    Published: 26 Jul 2014
    10
    Critical

    CVE-2014-2363

    Last Modified: 6 Oct 2025

    Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.

    Published: 26 Jul 2014
    4.3
    Medium

    CVE-2014-3071

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

    Published: 26 Jul 2014
    5
    Medium

    CVE-2014-3301

    Last Modified: 12 Apr 2025

    The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.

    Published: 26 Jul 2014
    6.8
    Medium

    CVE-2014-3305

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.

    Published: 26 Jul 2014
    4.3
    Medium

    CVE-2014-3324

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.

    Published: 26 Jul 2014
    6.5
    Medium

    CVE-2014-3326

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.

    Published: 26 Jul 2014