CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-4527

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2) AdministratorID parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4529

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4531

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the n parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4532

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in templates/printAdminUsersList_Footer.tpl.php in the GarageSale plugin before 1.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4537

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) sort, (2) search, or (3) dir parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4540

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in oleggo-twitter/twitter_login_form.php in the Oleggo LiveStream plugin 0.2.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4547

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in templates/default/index_ajax.php in the Rezgo Online Booking plugin before 1.8.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) tags or (2) search_for parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4552

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in library/includes/payment/paypalexpress/DoDirectPayment.php in the Spotlight (spotlightyour) plugin 4.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the paymentType parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4557

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for-jigoshop) plugin 3.1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4560

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/getTipo.php in the ToolPage plugin 1.6.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the t parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4566

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter) plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4570

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4572

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in bvc.php in the Votecount for Balatarin plugin 0.1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) bvcurl parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4573

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php in the Walk Score plugin 0.5.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) o parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4574

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in resize.php in the WebEngage plugin before 2.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the height parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4578

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in asset-studio/icons-launcher.php in the WP App Maker plugin 1.0.16.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4579

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4580

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in blipbot.ajax.php in the WP BlipBot plugin 3.0.9 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the BlipBotID parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4582

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the dialog_id parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4587

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap plugin 1.8 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) zl, (2) mt, or (3) dc parameter to guest-locator.php; the (4) zl, (5) mt, (6) activate, or (7) dc parameter to online-tracker.php; the (8) zl, (9) mt, or (10) dc parameter to stats-map.php; or the (11) zl, (12) mt, (13) activate, or (14) dc parameter to weather-map.php.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4588

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4589

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in uploader.php in the WP Silverlight Media Player (wp-media-player) plugin 0.8 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4590

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in get.php in the WP Microblogs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the oauth_verifier parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4594

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in the WordPress Responsive Preview plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4595

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WP RESTful plugin 0.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) oauth_callback parameter to html_api_authorize.php or the (2) oauth_token_temp or (3) oauth_callback_temp parameter to html_api_login.php.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4596

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in js/button-snapapp.php in the SnapApp plugin 1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) msg or (2) act parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4598

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php in the wp-tmkm-amazon plugin 1.5b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the AID parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4599

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugin 1.0.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) search_term, (3) page_id, (4) page, or (5) page_links parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4603

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4604

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in settings/pwsettings.php in the Your Text Manager plugin 0.3.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the ytmpw parameter.

    Published: 2 Jul 2014
    5
    Medium

    CVE-2014-3889

    Last Modified: 12 Apr 2025

    silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the Options field of a TCP header, a different vulnerability than CVE-2014-3890.

    Published: 2 Jul 2014
    5
    Medium

    CVE-2014-3890

    Last Modified: 12 Apr 2025

    silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet, a different vulnerability than CVE-2014-3889.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4694

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in suricata_select_alias.php in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via unspecified variables.

    Published: 2 Jul 2014
    5.8
    Medium

    CVE-2014-4695

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to snort_rules_flowbits.php or (2) the returl parameter to snort_select_alias.php.

    Published: 2 Jul 2014
    7.2
    High

    CVE-2014-3074

    Last Modified: 12 Apr 2025

    The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.

    Published: 2 Jul 2014
    4
    Medium

    CVE-2014-3297

    Last Modified: 12 Apr 2025

    Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937, CSCui37004, and CSCui36927.

    Published: 2 Jul 2014
    4
    Medium

    CVE-2014-3298

    Last Modified: 12 Apr 2025

    Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug ID CSCui36976.

    Published: 2 Jul 2014
    5
    Medium

    CVE-2014-3066

    Last Modified: 12 Apr 2025

    IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 2 Jul 2014
    6.8
    Medium

    CVE-2014-3307

    Last Modified: 12 Apr 2025

    The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4687

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the starttime0 parameter to firewall_schedule.php, (2) the rssfeed parameter to rss.widget.php, (3) the servicestatusfilter parameter to services_status.widget.php, (4) the txtRecallBuffer parameter to exec.php, or (5) the HTTP Referer header to log.widget.php.

    Published: 2 Jul 2014
    5.8
    Medium

    CVE-2014-4696

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.

    Published: 2 Jul 2014
    6.5
    Medium

    CVE-2014-4688

    Last Modified: 12 Apr 2025

    pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php.

    Published: 2 Jul 2014
    5
    Medium

    CVE-2014-4689

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in pkg_edit.php in pfSense before 2.1.4 allows remote attackers to read arbitrary XML files via a full pathname in the xml parameter.

    Published: 2 Jul 2014
    5
    Medium

    CVE-2014-4690

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in the pkg parameter to pkg_mgr_install.php and allow (2) remote authenticated users to read arbitrary files via the downloadbackup parameter to system_firmware_restorefullbackup.php.

    Published: 2 Jul 2014
    6.8
    Medium

    CVE-2014-4691

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in pfSense before 2.1.4 allows remote attackers to hijack web sessions via a firewall login cookie.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4692

    Last Modified: 12 Apr 2025

    pfSense before 2.1.4, when HTTP is used, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 2 Jul 2014
    4.3
    Medium

    CVE-2014-4693

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the eng parameter to snort_import_aliases.php or (2) unspecified variables to snort_select_alias.php.

    Published: 2 Jul 2014
    6.8
    Medium

    CVE-2014-4668

    Last Modified: 12 Apr 2025

    The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

    Published: 2 Jul 2014
    5.1
    Medium

    CVE-2014-3100

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on cryptographic operations, via a long key name.

    Published: 2 Jul 2014
    7.5
    High

    CVE-2014-3482

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.

    Published: 2 Jul 2014