10
    Critical

    CVE-2014-9208

    Last Modified: 8 Sept 2015

    Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.

    Source:Praveen Darshanam
    Published:11 Sept 2015
    10
    Critical

    CVE-2014-9195

    Last Modified: 17 Dec 2016

    Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

    Source:Photubias
    Published:17 Jan 2015
    5
    Medium

    CVE-2014-9181

    Last Modified: 28 Feb 2014

    Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/.

    Source:SEC Consult
    Published:2 Dec 2014
    4
    Medium

    CVE-2014-9179

    Last Modified: 12 Nov 2014

    Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.

    Source:Halil Dalabasmaz
    Published:2 Dec 2014
    7.5
    High

    CVE-2014-9178

    Last Modified: 25 Nov 2014

    Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id parameter in the (2) download_project, (3) download_archive, or (4) remove_cat function.

    Source:ITAS Team
    Published:2 Dec 2014
    7.5
    High

    CVE-2014-9175

    Last Modified: 25 Nov 2014

    SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.

    Source:Claudio Viviani
    Published:2 Dec 2014
    7.5
    High

    CVE-2014-9173

    Last Modified: 25 Nov 2014

    SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.

    Source:Kacper Szurek
    Published:2 Dec 2014
    9.8
    Critical

    CVE-2014-9148

    Last Modified: 31 Mar 2015

    Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.

    Source:Mahendra
    Published:16 Oct 2017
    7.5
    High

    CVE-2014-9147

    Last Modified: 31 Mar 2015

    Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

    Source:Mahendra
    Published:16 Oct 2017
    4.3
    Medium

    CVE-2014-9146

    Last Modified: 31 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) id, (3) page, or (4) app parameter to the default URI or the (5) act parameter to dapur/index.php.

    Source:Mahendra
    Published:14 Apr 2015
    7.5
    High

    CVE-2014-9145

    Last Modified: 31 Mar 2015

    Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.

    Source:Mahendra
    Published:14 Apr 2015
    7.5
    High

    CVE-2014-9144

    Last Modified: 4 Dec 2014

    Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter).

    Source:Crash
    Published:5 Dec 2014
    4.3
    Medium

    CVE-2014-9143

    Last Modified: 4 Dec 2014

    Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.

    Source:Crash
    Published:5 Dec 2014
    4.3
    Medium

    CVE-2014-9142

    Last Modified: 4 Dec 2014

    Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.

    Source:Crash
    Published:5 Dec 2014
    7.2
    High

    CVE-2014-9141

    Last Modified: 4 Dec 2014

    The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.

    Source:Information Paradox
    Published:3 Dec 2014
    5
    Medium

    CVE-2014-9119

    Last Modified: 3 Dec 2014

    Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Ashiyane Digital Security Team
    Published:31 Dec 2014
    8.8
    High

    CVE-2014-9118

    Last Modified: 13 Oct 2015

    The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.

    Source:Lyon Yang
    Published:17 Oct 2017
    7.5
    High

    CVE-2014-9115

    Last Modified: 13 Nov 2014

    SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

    Source:Manuel García Cárdenas
    Published:23 Dec 2014
    7.2
    High

    CVE-2014-9113

    Last Modified: 28 Nov 2014

    CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.

    Source:Information Paradox
    Published:2 Dec 2014
    6.8
    Medium

    CVE-2014-9101

    Last Modified: 28 Jul 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks or possibly have other unspecified impact via the (1) label parameter to admin/users/roles/, (2) lang[1][base][questions_account_type_5615100a931845eca8da20cfdf7327e0] in an AddAccountType action or (3) qst_name parameter in an addQuestion action to admin/questions/ajax-responder/, or (4) form_name or (5) restrictedUsername parameter to admin/restricted-usernames.

    Source:LiquidWorm
    Published:26 Nov 2014
    6.8
    Medium

    CVE-2014-9099

    Last Modified: 19 Jan 2016

    Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page in wp-admin/options-general.php.

    Source:Dylan Irzi
    Published:26 Nov 2014
    3.5
    Low

    CVE-2014-9098

    Last Modified: 24 Jul 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoadssearchQuery parameter to (1) videoads/videoads.php, (2) video/video.php, or (3) playlist/playlist.php.

    Source:Claudio Viviani
    Published:26 Nov 2014
    7.5
    High

    CVE-2014-9097

    Last Modified: 24 Jul 2014

    Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in a myextract action to wp-admin/admin-ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the playlistId parameter in the newplaylist page or (3) videoId parameter in a newvideo page to wp-admin/admin.php.

    Source:Claudio Viviani
    Published:26 Nov 2014
    7.5
    High

    CVE-2014-9096

    Last Modified: 5 Jan 2017

    Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.

    Source:BlackHawk
    Published:26 Nov 2014
    7.5
    High

    CVE-2014-9095

    Last Modified: 21 Jul 2014

    Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records.

    Source:Brandon Perry
    Published:26 Nov 2014
    4.3
    Medium

    CVE-2014-9094

    Last Modified: 17 Jan 2016

    Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter.

    Source:MustLive
    Published:26 Nov 2014
    5
    Medium

    CVE-2014-9034

    Last Modified: 1 Dec 2014

    wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

    Source:SECURELI.com
    Published:25 Nov 2014
    5
    Medium

    CVE-2014-9016

    Last Modified: 1 Dec 2014

    The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

    Source:Javer Nieto & Andres Rojas
    Published:24 Nov 2014
    4.3
    Medium

    CVE-2014-9014

    Last Modified: 24 Mar 2015

    Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.

    Source:Kacper Szurek
    Published:6 Nov 2019
    8.8
    High

    CVE-2014-9013

    Last Modified: 24 Mar 2015

    The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

    Source:Kacper Szurek
    Published:6 Nov 2019
    7.5
    High

    CVE-2014-9005

    Last Modified: 17 Nov 2014

    Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php.

    Source:Mr T
    Published:20 Nov 2014
    4.3
    Medium

    CVE-2014-9004

    Last Modified: 17 Nov 2014

    Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a member_profile action to index.php.

    Source:Mr T
    Published:20 Nov 2014
    6.5
    Medium

    CVE-2014-9001

    Last Modified: 27 Oct 2014

    reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) APPTMIN, (2) APPTHR, (3) APPTDA, (4) APPTMO, (5) APPTYR, or (6) APPTPHONE parameters.

    Source:Simo Ben Youssef
    Published:20 Nov 2014
    6.5
    Medium

    CVE-2014-9000

    Last Modified: 27 Oct 2014

    Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.

    Source:Brandon Perry
    Published:20 Nov 2014
    6.5
    Medium

    CVE-2014-8998

    Last Modified: 23 Dec 2016

    lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch.

    Source:Metasploit
    Published:20 Nov 2014
    7.5
    High

    CVE-2014-8997

    Last Modified: 13 Nov 2014

    Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/uploads/images/.

    Source:Halil Dalabasmaz
    Published:20 Nov 2014
    5
    Medium

    CVE-2014-8995

    Last Modified: 21 Nov 2014

    SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.

    Source:ZoRLu Bugrahan
    Published:20 Nov 2014
    4.3
    Medium

    CVE-2014-8954

    Last Modified: 12 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Description fields in a playlist or the (3) filter parameter in an explore action to index.php.

    Source:Halil Dalabasmaz
    Published:17 Nov 2014
    6.8
    Medium

    CVE-2014-8953

    Last Modified: 11 Nov 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of administrators or requests that (1) add an admin account via a request to filepath/yonetim/plugin/adminsave.php or have unspecified impact via a request to (2) ayarsave.php, (3) uyesave.php, (4) slaytadd.php, or (5) slaytsave.php.

    Source:ZoRLu Bugrahan
    Published:17 Nov 2014
    6
    Medium

    CVE-2014-8949

    Last Modified: 28 Apr 2014

    The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue itself crosses privileges.

    Source:Everett Griffiths
    Published:16 Nov 2014
    6.8
    Medium

    CVE-2014-8948

    Last Modified: 28 Apr 2014

    Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbitrary commands.

    Source:Everett Griffiths
    Published:16 Nov 2014
    7.2
    High

    CVE-2014-8904

    Last Modified: 30 Oct 2015

    lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

    Source:S2 Crew
    Published:15 Jan 2015
    10
    Critical

    CVE-2014-8877

    Last Modified: 4 Dec 2014

    The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.

    Source:Phi Ngoc Le
    Published:5 Dec 2014
    7.8
    High

    CVE-2014-8868

    Last Modified: 2 Dec 2014

    EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.

    Source:RedTeam Pentesting
    Published:7 Dec 2014
    9.3
    Critical

    CVE-2014-8835

    Last Modified: 10 Jan 2015

    The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data data type, which allows attackers to execute arbitrary code by providing a crafted dictionary to sysmond, related to an "XPC type confusion" issue.

    Source:Google Security Research
    Published:30 Jan 2015
    5
    Medium

    CVE-2014-8826

    Last Modified: 29 Jan 2015

    LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive.

    Source:Amplia Security Research
    Published:30 Jan 2015
    6.5
    Medium

    CVE-2014-8810

    Last Modified: 15 Dec 2014

    SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.

    Source:Kacper Szurek
    Published:24 Dec 2014
    5
    Medium

    CVE-2014-8802

    Last Modified: 3 Feb 2015

    The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

    Source:Kacper Szurek
    Published:23 Jan 2015
    5
    Medium

    CVE-2014-8801

    Last Modified: 26 Sept 2016

    Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

    Source:Kacper Szurek
    Published:28 Nov 2014
    4.3
    Medium

    CVE-2014-8800

    Last Modified: 2 Dec 2014

    Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action.

    Source:Kacper Szurek
    Published:5 Dec 2014