CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-1421

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.

    Published: 22 Apr 2014
    3.3
    Low

    CVE-2013-2105

    Last Modified: 12 Apr 2025

    The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.

    Published: 22 Apr 2014
    4.3
    Medium

    CVE-2013-2187

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.

    Published: 22 Apr 2014
    6.5
    Medium

    CVE-2014-2654

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in MobFox mAdserve 2.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) edit_ad_unit.php, (2) view_adunits.php, or (3) edit_campaign.php in www/cp/.

    Published: 22 Apr 2014
    6.8
    Medium

    CVE-2014-2659

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 22 Apr 2014
    7.5
    High

    CVE-2014-2737

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function.

    Published: 22 Apr 2014
    6.8
    Medium

    CVE-2014-1615

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to api/user.

    Published: 22 Apr 2014
    4.3
    Medium

    CVE-2014-2907

    Last Modified: 12 Apr 2025

    The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 22 Apr 2014
    5
    Medium

    CVE-2014-3243

    Last Modified: 12 Apr 2025

    SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

    Published: 22 Apr 2014
    9
    Critical

    CVE-2014-0187

    Last Modified: 12 Apr 2025

    The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

    Published: 22 Apr 2014
    5.5
    Medium

    CVE-2014-2915

    Last Modified: 12 Apr 2025

    Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.

    Published: 22 Apr 2014
    5
    Medium

    CVE-2014-3242

    Last Modified: 12 Apr 2025

    SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 22 Apr 2014
    8.8
    High

    CVE-2014-9938

    Last Modified: 20 Apr 2025

    contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

    Published: 22 Apr 2014
    5.5
    Medium

    CVE-2013-5459

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x before 4.0.6 allows remote authenticated users to modify data by leveraging improper parameter checking.

    Published: 21 Apr 2014
    7.5
    High

    CVE-2014-2921

    Last Modified: 12 Apr 2025

    The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via vectors involving a Zend_Pdf_ElementFactory_Proxy object and a pathname with a trailing \0 character.

    Published: 21 Apr 2014
    6.4
    Medium

    CVE-2014-2922

    Last Modified: 12 Apr 2025

    The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an object obtained by unserializing a pathname, which allows remote attackers to conduct PHP object injection attacks and delete arbitrary files via vectors involving a Zend_Http_Response_Stream object.

    Published: 21 Apr 2014
    3
    Low

    CVE-2014-0361

    Last Modified: 12 Apr 2025

    The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file.

    Published: 21 Apr 2014
    3.5
    Low

    CVE-2014-0932

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulfillment Foundation 9.0 before HF85 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 21 Apr 2014
    6.4
    Medium

    CVE-2014-2269

    Last Modified: 12 Apr 2025

    modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.

    Published: 21 Apr 2014
    6.8
    Medium

    CVE-2014-2341

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Published: 21 Apr 2014
    4.3
    Medium

    CVE-2014-2925

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi.

    Published: 21 Apr 2014
    8.5
    High

    CVE-2013-5948

    Last Modified: 12 Apr 2025

    The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter).

    Published: 21 Apr 2014
    5.8
    Medium

    CVE-2014-0173

    Last Modified: 12 Apr 2025

    The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service, which allows remote attackers to bypass intended restrictions and publish posts via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 21 Apr 2014
    7.5
    High

    CVE-2014-1216

    Last Modified: 12 Apr 2025

    FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.

    Published: 21 Apr 2014
    5.8
    Medium

    CVE-2014-2735

    Last Modified: 12 Apr 2025

    WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 21 Apr 2014
    6.3
    Medium

    CVE-2014-2719

    Last Modified: 12 Apr 2025

    Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator user name and password by reading the source code.

    Published: 21 Apr 2014
    4.3
    Medium

    CVE-2014-0198

    Last Modified: 12 Apr 2025

    The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

    Published: 21 Apr 2014
    5
    Medium

    CVE-2014-0473

    Last Modified: 12 Apr 2025

    The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users.

    Published: 21 Apr 2014
    5.1
    Medium

    CVE-2014-0472

    Last Modified: 12 Apr 2025

    The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

    Published: 21 Apr 2014
    10
    Critical

    CVE-2014-0474

    Last Modified: 12 Apr 2025

    The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

    Published: 21 Apr 2014
    4
    Medium

    CVE-2014-2665

    Last Modified: 12 Apr 2025

    includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.

    Published: 20 Apr 2014
    4
    Medium

    CVE-2014-1517

    Last Modified: 12 Apr 2025

    The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue.

    Published: 20 Apr 2014
    5.5
    Medium

    CVE-2015-3149

    Last Modified: 20 Apr 2025

    The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

    Published: 20 Apr 2014
    8.5
    High

    CVE-2013-6215

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 10.01 and 10.10 allows remote authenticated users to execute arbitrary code via unknown vectors, aka ZDI-CAN-1977.

    Published: 19 Apr 2014
    6.5
    Medium

    CVE-2013-6212

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Database and Middleware Automation 10.0, 10.01, 10.10, and 10.20 before 10.20.100 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 19 Apr 2014
    10
    Critical

    CVE-2013-6218

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 19 Apr 2014
    3.8
    Low

    CVE-2013-6219

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

    Published: 19 Apr 2014
    5
    Medium

    CVE-2014-2155

    Last Modified: 12 Apr 2025

    The DHCPv6 server module in Cisco CNS Network Registrar 7.1 allows remote attackers to cause a denial of service (daemon reload) via a malformed DHCPv6 packet, aka Bug ID CSCuo07437.

    Published: 19 Apr 2014
    6.8
    Medium

    CVE-2014-1984

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 19 Apr 2014
    4.3
    Medium

    CVE-2014-0778

    Last Modified: 24 Sept 2025

    TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a remote unauthenticated user access to release OS version information. While this is a minor vulnerability, it represents a method for further network reconnaissance.

    Published: 19 Apr 2014
    6.4
    Medium

    CVE-2014-1974

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the LYSESOFT AndExplorer application before 20140403 and AndExplorerPro application before 20140405 for Android allows attackers to overwrite or create arbitrary files via unspecified vectors.

    Published: 19 Apr 2014
    7.8
    High

    CVE-2014-1983

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vectors.

    Published: 19 Apr 2014
    9.3
    Critical

    CVE-2014-2731

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary code via HTTP traffic to port (1) 4999 or (2) 80.

    Published: 19 Apr 2014
    5
    Medium

    CVE-2014-2732

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to access arbitrary files via HTTP traffic to port (1) 4999 or (2) 80.

    Published: 19 Apr 2014
    5
    Medium

    CVE-2014-2733

    Last Modified: 12 Apr 2025

    Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via crafted HTTP requests to port (1) 4999 or (2) 80.

    Published: 19 Apr 2014
    6.8
    Medium

    CVE-2014-1990

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords.

    Published: 19 Apr 2014
    10
    Critical

    CVE-2013-6213

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1833.

    Published: 19 Apr 2014
    4
    Medium

    CVE-2013-6214

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 9.05, 10.01, and 10.10 allows remote authenticated users to obtain sensitive information via unknown vectors, aka ZDI-CAN-2042.

    Published: 19 Apr 2014
    5.5
    Medium

    CVE-2013-7195

    Last Modified: 12 Apr 2025

    PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specifies the ID for the publication.

    Published: 18 Apr 2014
    5.5
    Medium

    CVE-2013-7196

    Last Modified: 12 Apr 2025

    static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.

    Published: 18 Apr 2014