6.5
    Medium

    CVE-2014-10033

    Last Modified: 16 Feb 2014

    SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.

    Source:Ahmed Aboul-Ela
    Published:13 Jan 2015
    6.5
    Medium

    CVE-2014-10032

    Last Modified: 8 Jan 2014

    SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Source:Jefrey
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10031

    Last Modified: 26 Apr 2018

    Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command.

    Source:Muhammad Alharmeel
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10029

    Last Modified: 12 Oct 2018

    SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.

    Source:secthrowaway
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10023

    Last Modified: 5 Feb 2014

    Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/.

    Source:AtT4CKxT3rR0r1ST
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10021

    Last Modified: 13 Jan 2015

    Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in server/php/.

    Source:Metasploit
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10020

    Last Modified: 23 Jan 2014

    SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:vinicius777
    Published:13 Jan 2015
    6.8
    Medium

    CVE-2014-10019

    Last Modified: 20 Apr 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID or (2) change the password via a crafted request.

    Source:Rakesh S
    Published:13 Jan 2015
    4.3
    Medium

    CVE-2014-10018

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote attackers to inject arbitrary web script or HTML via the essid parameter.

    Source:Rakesh S
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10015

    Last Modified: 14 Jan 2014

    SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:HackXBack
    Published:13 Jan 2015
    6.8
    Medium

    CVE-2014-10014

    Last Modified: 14 Jan 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site scripting (XSS) attacks via the (2) event_title parameter in a create action to the AdminEvents controller or (3) category_title parameter in a create action to the AdminCategories controller.

    Source:HackXBack
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10013

    Last Modified: 10 Nov 2014

    SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.

    Source:dill
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10011

    Last Modified: 25 Nov 2014

    Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote attackers to execute arbitrary code via a long string to the (1) CGI_ParamSet, (2) OpenFileDlg, (3) SnapFileName, (4) Password, (5) SetCGIAPNAME, (6) AccountCode, or (7) RemoteHost function.

    Source:LiquidWorm
    Published:13 Jan 2015
    5
    Medium

    CVE-2014-10010

    Last Modified: 14 Jan 2014

    Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.

    Source:HackXBack
    Published:13 Jan 2015
    4.3
    Medium

    CVE-2014-10009

    Last Modified: 20 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to the add_insurance_cat page; or (6) status[] parameter to the add_status page.

    Source:LiquidWorm
    Published:13 Jan 2015
    6.8
    Medium

    CVE-2014-10008

    Last Modified: 20 Feb 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for requests that add (1) an administrator via a crafted request to the admin page, (2) an agent via a crafted request to the agent page, (3) a sub-agent via a crafted request to the sub_agent page, (4) a partner via a crafted request to the partner page, or (5) a client via a crafted request to the client page.

    Source:LiquidWorm
    Published:13 Jan 2015
    6.8
    Medium

    CVE-2014-10001

    Last Modified: 14 Jan 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.

    Source:HackXBack
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-9735

    Last Modified: 8 May 2015

    The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors.

    Source:Metasploit
    Published:30 Jun 2015
    5
    Medium

    CVE-2014-9734

    Last Modified: 1 Sept 2014

    Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.

    Source:Hugo Santiago
    Published:30 Jun 2015
    10
    Critical

    CVE-2014-9727

    Last Modified: 1 May 2014

    AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

    Source:0x4148
    Published:29 May 2015
    7.2
    High

    CVE-2014-9643

    Last Modified: 4 Feb 2015

    K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

    Source:Parvez Anwar
    Published:6 Feb 2015
    7.2
    High

    CVE-2014-9642

    Last Modified: 4 Feb 2015

    bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x0022405c IOCTL call.

    Source:Parvez Anwar
    Published:6 Feb 2015
    7.2
    High

    CVE-2014-9641

    Last Modified: 3 Feb 2015

    The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222400 IOCTL call.

    Source:Parvez Anwar
    Published:6 Feb 2015
    7.5
    High

    CVE-2014-9633

    Last Modified: 8 Aug 2017

    The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL pointer dereference.

    Source:Parvez Anwar
    Published:3 Feb 2015
    7.2
    High

    CVE-2014-9632

    Last Modified: 4 Feb 2015

    The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.

    Source:Parvez Anwar
    Published:6 Feb 2015
    7.2
    High

    CVE-2014-9619

    Last Modified: 21 Aug 2015

    Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif.

    Source:Anastasios Monachos
    Published:19 Sept 2017
    9.8
    Critical

    CVE-2014-9618

    Last Modified: 18 Jan 2018

    The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.

    Source:Anastasios Monachos
    Published:19 Sept 2017
    9.8
    Critical

    CVE-2014-9613

    Last Modified: 21 Aug 2015

    Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.

    Source:Anastasios Monachos
    Published:19 Feb 2020
    9.8
    Critical

    CVE-2014-9612

    Last Modified: 21 Aug 2015

    SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.

    Source:Anastasios Monachos
    Published:19 Feb 2020
    9.8
    Critical

    CVE-2014-9611

    Last Modified: 21 Aug 2015

    Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php.

    Source:Anastasios Monachos
    Published:19 Sept 2017
    5.3
    Medium

    CVE-2014-9610

    Last Modified: 18 Jan 2018

    Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user/quarantine_disable.php.

    Source:Anastasios Monachos
    Published:19 Sept 2017
    9.4
    Critical

    CVE-2014-9605

    Last Modified: 21 Aug 2015

    WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character in the login and password parameters to webupgrade/webupgrade.php. NOTE: this was originally reported as an SQL injection vulnerability, but this may be inaccurate.

    Source:Anastasios Monachos
    Published:4 Sept 2015
    6.8
    Medium

    CVE-2014-9598

    Last Modified: 14 Jul 2017

    The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.

    Source:Veysel HATAS
    Published:21 Jan 2015
    6.8
    Medium

    CVE-2014-9597

    Last Modified: 14 Jul 2017

    The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.

    Source:Veysel HATAS
    Published:21 Jan 2015
    10
    Critical

    CVE-2014-9583

    Last Modified: 2 May 2018

    common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD packet to UDP port 9999. NOTE: this issue was incorrectly mapped to CVE-2014-10000, but that ID is invalid due to its use as an example of the 2014 CVE ID syntax change.

    Source:Metasploit
    Published:8 Jan 2015
    4.3
    Medium

    CVE-2014-9582

    Last Modified: 27 Dec 2014

    Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

    Source:TaurusOmar
    Published:8 Jan 2015
    5
    Medium

    CVE-2014-9581

    Last Modified: 27 Dec 2014

    Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

    Source:TaurusOmar
    Published:8 Jan 2015
    4.3
    Medium

    CVE-2014-9580

    Last Modified: 27 Dec 2014

    Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155; see CVE-2014-1155 for more information.

    Source:TaurusOmar
    Published:8 Jan 2015
    7.5
    High

    CVE-2014-9567

    Last Modified: 31 Dec 2014

    Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the upload/files/ or upload/temp/ directory.

    Source:Metasploit
    Published:7 Jan 2015
    7.5
    High

    CVE-2014-9566

    Last Modified: 4 Mar 2015

    Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.

    Source:Brandon Perry
    Published:10 Mar 2015
    9.8
    Critical

    CVE-2014-9558

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in SmartCMS v.2.

    Source:Ariko-Security
    Published:28 Aug 2017
    7.5
    High

    CVE-2014-9528

    Last Modified: 10 Dec 2014

    SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks via a request that causes an error.

    Source:Jos Wetzels_ Emiel Florijn
    Published:6 Jan 2015
    4.3
    Medium

    CVE-2014-9522

    Last Modified: 16 Dec 2014

    Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML via the (1) author field to guestbook.php or (2) username field to account.php.

    Source:Steffen Rösemann
    Published:5 Jan 2015
    4.3
    Medium

    CVE-2014-9516

    Last Modified: 31 Dec 2014

    Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site" input in the Profile section.

    Source:Halil Dalabasmaz
    Published:5 Jan 2015
    8.8
    High

    CVE-2014-9495

    Last Modified: 9 Jun 2025

    Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.

    Published:22 Dec 2014
    7.5
    High

    CVE-2014-9473

    Last Modified: 3 Feb 2015

    Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a direct request to the file in the default upload directory.

    Source:Zakhar
    Published:8 Jan 2015
    7.5
    High

    CVE-2014-9464

    Last Modified: 7 Jan 2015

    SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, related to the $parent_id variable.

    Source:Pham Kien Cuong
    Published:3 Jan 2015
    8.8
    High

    CVE-2014-9463

    Last Modified: 3 May 2018

    functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.

    Source:Net.Edit0r
    Published:15 Sept 2017
    6.5
    Medium

    CVE-2014-9457

    Last Modified: 27 Dec 2014

    SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.

    Source:xd4rker dark
    Published:2 Jan 2015
    10
    Critical

    CVE-2014-9456

    Last Modified: 10 Oct 2016

    Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file. NOTE: this issue was originally incorrectly mapped to CVE-2014-1004; see CVE-2014-1004 for more information.

    Source:TaurusOmar
    Published:2 Jan 2015