CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2014-2198

    Last Modified: 12 Apr 2025

    Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root accounts by extracting this key from a binary file found in a different installation of the product, aka Bug ID CSCud41130.

    Published: 7 Jul 2014
    7.5
    High

    CVE-2014-3300

    Last Modified: 12 Apr 2025

    The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.

    Published: 7 Jul 2014
    6.4
    Medium

    CVE-2014-3308

    Last Modified: 12 Apr 2025

    Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.

    Published: 7 Jul 2014
    7.8
    High

    CVE-2013-4364

    Last Modified: 21 Nov 2024

    (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.

    Published: 7 Jul 2014
    5
    Medium

    CVE-2014-4720

    Last Modified: 12 Apr 2025

    Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking into the phrase," a different vulnerability than CVE-2014-0477.

    Published: 6 Jul 2014
    6.9
    Medium

    CVE-2014-4699

    Last Modified: 12 Apr 2025

    The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.

    Published: 4 Jul 2014
    5
    Medium

    CVE-2014-4168

    Last Modified: 12 Apr 2025

    (1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.

    Published: 3 Jul 2014
    7.5
    High

    CVE-2014-4672

    Last Modified: 12 Apr 2025

    The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.

    Published: 3 Jul 2014
    4.3
    Medium

    CVE-2014-4002

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_templates.php, (6) graph_templates.php, (7) graphs.php, (8) host.php, or (9) host_templates.php or the (10) graph_template_input_id or (11) graph_template_id parameter to graph_templates_inputs.php.

    Published: 3 Jul 2014
    6.8
    Medium

    CVE-2014-4717

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to wp-admin/options-general.php, which is not properly handled in the homepage, and unspecified vectors related to (2) Pages, (3) Posts, (4) Category/Archive pages or (5) post Excerpts.

    Published: 3 Jul 2014
    4.3
    Medium

    CVE-2014-4195

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the article_id parameter.

    Published: 3 Jul 2014
    4.3
    Medium

    CVE-2014-2965

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in auth-settings-x.php in SpamTitan before 6.04 allows remote attackers to inject arbitrary web script or HTML via the sortdir parameter.

    Published: 3 Jul 2014
    9.3
    Critical

    CVE-2014-0325

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that triggers improper processing of CElement objects, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1751 and CVE-2014-1755. NOTE: MS14-018 originally had a typo of CVE-2014-0235 for this.

    Published: 3 Jul 2014
    6.8
    Medium

    CVE-2014-3920

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the default URI.

    Published: 3 Jul 2014
    6.8
    Medium

    CVE-2014-4716

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for requests that change passwords via the Password and PasswordReEnter parameters to goform/RgSecurity.

    Published: 3 Jul 2014
    6.8
    Medium

    CVE-2014-4718

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site scripting (XSS) attacks via the (2) email or (3) subject parameter in contact_form.ext.php to admin/extensions.php.

    Published: 3 Jul 2014
    4.3
    Medium

    CVE-2014-3149

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before 20140424, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jul 2014
    6.5
    Medium

    CVE-2014-3857

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.

    Published: 3 Jul 2014
    4.3
    Medium

    CVE-2014-4719

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the username field.

    Published: 3 Jul 2014
    5
    Medium

    CVE-2014-4715

    Last Modified: 12 Apr 2025

    Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.

    Published: 3 Jul 2014
    9.8
    Critical

    CVE-2008-7313

    Last Modified: 20 Apr 2025

    The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.

    Published: 3 Jul 2014
    9.8
    Critical

    CVE-2014-5008

    Last Modified: 20 Apr 2025

    Snoopy allows remote attackers to execute arbitrary commands.

    Published: 3 Jul 2014
    9.8
    Critical

    CVE-2014-5009

    Last Modified: 20 Apr 2025

    Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

    Published: 3 Jul 2014
    2.6
    Low

    CVE-2014-3737

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.php, related to the currencyUrl function.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4534

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4546

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the response parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4549

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4554

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in templates/download.php in the SS Downloads plugin before 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4555

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in fonts/font-form.php in the Style It plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4563

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in go.php in the URL Cloak & Encrypt (url-cloak-encrypt) plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4565

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4571

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4581

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in facture.php in the WPCB plugin 2.4.8 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4591

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4597

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in test.php in the WP Social Invitations plugin before 1.4.4.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4606

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in redirect_to_zeenshare.php in the ZeenShare plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the zs_sid parameter.

    Published: 2 Jul 2014
    6.8
    Medium

    CVE-2014-4614

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUser, (2) pwg.groups.deleteUser, (3) pwg.groups.setInfo, (4) pwg.users.setInfo, (5) pwg.permissions.add, or (6) pwg.permissions.remove method.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4522

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in client-assist.php in the dsSearchAgent: WordPress Edition plugin 1.0-beta10 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4541

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in shortcode-generator/preview-shortcode-external.php in the OMFG Mobile Pro plugin 1.1.26 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4576

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4600

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4526

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in callback.php in the efence plugin 1.3.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) zoneid, (3) pubKey, or (4) privKey parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4524

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in classes/custom-image/media.php in the WP Easy Post Types plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ref parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4542

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in redirect.php in the Ooorl plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4543

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in payper/payper.php in the Pay Per Media Player plugin 1.24 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fcolor, (2) links, (3) stitle, (4) height, (5) width, (6) host, (7) bcolor, (8) msg, (9) id, or (10) size parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4551

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in diagnostics/test.php in the Social Connect plugin 1.0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the testing parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4568

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4593

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4601

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in wu-ratepost.php in the Wu-Rating plugin 1.0 12319 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the v parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4605

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in cal/test.php in the ZdStatistics (zdstats) plugin 2.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 2 Jul 2014