5
    Medium

    CVE-2014-8799

    Last Modified: 26 Sept 2016

    Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

    Source:Kacper Szurek
    Published:28 Nov 2014
    6
    Medium

    CVE-2014-8791

    Last Modified: 15 Dec 2014

    project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.

    Source:Metasploit
    Published:2 Dec 2014
    5
    Medium

    CVE-2014-8775

    Last Modified: 17 Nov 2014

    MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Source:Narendra Bhati
    Published:3 Dec 2014
    4.3
    Medium

    CVE-2014-8774

    Last Modified: 17 Nov 2014

    Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.

    Source:Narendra Bhati
    Published:3 Dec 2014
    6.8
    Medium

    CVE-2014-8773

    Last Modified: 17 Nov 2014

    MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter.

    Source:Narendra Bhati
    Published:3 Dec 2014
    9
    Critical

    CVE-2014-8770

    Last Modified: 24 Oct 2016

    Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file, then accessing the PHP file via a direct request to it in magmi/plugins/.

    Source:Parvinder Bhasin
    Published:13 Nov 2014
    5
    Medium

    CVE-2014-8768

    Last Modified: 24 Nov 2014

    Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.

    Source:Steffen Bauch
    Published:13 Nov 2014
    8.3
    High

    CVE-2014-8757

    Last Modified: 12 Apr 2025

    LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.

    Published:17 Feb 2015
    9.8
    Critical

    CVE-2014-8741

    Last Modified: 13 Jan 2015

    Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.

    Source:Metasploit
    Published:27 Jan 2020
    9.8
    Critical

    CVE-2014-8739

    Last Modified: 21 Apr 2015

    Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

    Source:Metasploit
    Published:8 Feb 2020
    9.8
    Critical

    CVE-2014-8731

    Last Modified: 20 Apr 2025

    PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.

    Published:23 Mar 2017
    Unknown

    CVE-2014-8729

    https://github.com/inso-/TORQUE-Resource-Manager-2.5.x-2.5.13-stack-based-buffer-overflow-exploit-CVE-2014-8729-CVE-2014-878

    7.5
    High

    CVE-2014-8728

    Last Modified: 17 Nov 2014

    SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System and FMS) 7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ranger_user[name] parameter.

    Source:Anastasios Monachos
    Published:2 Dec 2014
    6.2
    Medium

    CVE-2014-8727

    Last Modified: 13 Nov 2014

    Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.

    Source:Anastasios Monachos
    Published:17 Nov 2014
    7.5
    High

    CVE-2014-8722

    Last Modified: 2 Jun 2021

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.

    Source:Ron Jost
    Published:17 Mar 2017
    4.3
    Medium

    CVE-2014-8690

    Last Modified: 12 Feb 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before 2.3.1 patch 4 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) src parameter in a none action to index.php, or the (3) "First Name" or (4) "Last Name" field to users/edituser.

    Source:Mayuresh Dani
    Published:19 Feb 2015
    9.8
    Critical

    CVE-2014-8687

    Last Modified: 1 Mar 2015

    Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

    Source:OJ Reeves
    Published:8 Jun 2017
    9.8
    Critical

    CVE-2014-8686

    Last Modified: 1 Apr 2017

    CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.

    Source:Metasploit
    Published:19 Sept 2017
    9.8
    Critical

    CVE-2014-8684

    Last Modified: 1 Apr 2017

    CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

    Source:Metasploit
    Published:19 Sept 2017
    7.5
    High

    CVE-2014-8682

    Last Modified: 14 Nov 2017

    Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go.

    Source:Timo Schmid
    Published:21 Nov 2014
    7.5
    High

    CVE-2014-8681

    Last Modified: 14 Nov 2017

    SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remote attackers to execute arbitrary SQL commands via the label parameter to user/repos/issues.

    Source:Timo Schmid
    Published:21 Nov 2014
    5.3
    Medium

    CVE-2014-8677

    Last Modified: 13 Jul 2015

    The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.

    Source:Huy-Ngoc DAU
    Published:31 Aug 2017
    5.3
    Medium

    CVE-2014-8676

    Last Modified: 13 Jul 2015

    Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

    Source:Huy-Ngoc DAU
    Published:31 Aug 2017
    7.5
    High

    CVE-2014-8675

    Last Modified: 13 Jul 2015

    Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash.

    Source:Huy-Ngoc DAU
    Published:31 Aug 2017
    5.4
    Medium

    CVE-2014-8674

    Last Modified: 13 Jul 2015

    Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.

    Source:Huy-Ngoc DAU
    Published:6 Jan 2020
    9.8
    Critical

    CVE-2014-8673

    Last Modified: 13 Jul 2015

    Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.

    Source:Huy-Ngoc DAU
    Published:7 Jan 2020
    5
    Medium

    CVE-2014-8657

    Last Modified: 27 Oct 2014

    The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to cause a denial of service (disconnect all wifi clients) via a request to wirelessChannelStatus.html.

    Source:LiquidWorm
    Published:6 Nov 2014
    10
    Critical

    CVE-2014-8656

    Last Modified: 27 Oct 2014

    The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers to obtain access to certain sensitive information via unspecified vectors.

    Source:LiquidWorm
    Published:6 Nov 2014
    5
    Medium

    CVE-2014-8655

    Last Modified: 27 Oct 2014

    The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass authentication and obtain sensitive information via an (a) admin or a (b) root value in the userData cookie in a request to (1) CmgwWirelessSecurity.xml, (2) DocsisConfigFile.xml, or (3) CmgwBasicSetup.xml in xml/ or (4) basicDDNS.html, (5) basicLanUsers.html, or (6) rootDesc.xml.

    Source:LiquidWorm
    Published:6 Nov 2014
    6.8
    Medium

    CVE-2014-8654

    Last Modified: 27 Oct 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway hardware 1.0 with firmware CH6640-3.5.11.7-NOSH allow remote attackers to hijack the authentication of administrators for requests that (1) have unspecified impact on DDNS configuration via a request to basicDDNS.html, (2) change the wifi password via the psKey parameter to setWirelessSecurity.html, (3) add a static MAC address via the MacAddress parameter in an add_static action to setBasicDHCP1.html, or (4) enable or disable UPnP via the UPnP parameter in an apply action to setAdvancedOptions.html.

    Source:LiquidWorm
    Published:6 Nov 2014
    4.3
    Medium

    CVE-2014-8653

    Last Modified: 27 Oct 2014

    Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to inject arbitrary web script or HTML via the userData cookie.

    Source:LiquidWorm
    Published:6 Nov 2014
    5
    Medium

    CVE-2014-8652

    Last Modified: 26 Nov 2014

    Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of HTTP requests to index.html on TCP port 1681.

    Source:firebitsbr
    Published:10 Nov 2014
    7.5
    High

    CVE-2014-8636

    Last Modified: 24 Mar 2015

    The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.

    Source:Metasploit
    Published:15 Jan 2014
    4.6
    Medium

    CVE-2014-8612

    Last Modified: 29 Jan 2015

    Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function, when setting the SCTIP_SS_VALUE option, or (2) read arbitrary kernel memory via the stream id to the getsockopt function, when getting the SCTP_SS_PRIORITY option.

    Source:Core Security
    Published:2 Feb 2015
    3.3
    Low

    CVE-2014-8610

    Last Modified: 12 Apr 2025

    AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows attackers to send stored SMS messages, and consequently transmit arbitrary new draft SMS messages or trigger additional per-message charges from a network operator for old messages, via a crafted application that broadcasts an intent with the com.android.mms.transaction.MESSAGE_SENT action, aka Bug 17671795.

    Published:15 Dec 2014
    7.2
    High

    CVE-2014-8609

    Last Modified: 12 Apr 2025

    The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.

    Published:15 Dec 2014
    2.1
    Low

    CVE-2014-8607

    Last Modified: 10 Nov 2014

    The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command.

    Source:Larry W. Cashdollar
    Published:10 Jun 2015
    4
    Medium

    CVE-2014-8606

    Last Modified: 10 Nov 2014

    Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.

    Source:Larry W. Cashdollar
    Published:10 Jun 2015
    5
    Medium

    CVE-2014-8605

    Last Modified: 10 Nov 2014

    The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.

    Source:Larry W. Cashdollar
    Published:10 Jun 2015
    5
    Medium

    CVE-2014-8604

    Last Modified: 10 Nov 2014

    The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Source:Larry W. Cashdollar
    Published:10 Jun 2015
    6.5
    Medium

    CVE-2014-8603

    Last Modified: 10 Nov 2014

    cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filename'], (6) $_CONFIG['exfile_tar'], (7) $_CONFIG[sqldump], (8) $_CONFIG['mysql_host'], (9) $_CONFIG['mysql_pass'], (10) $_CONFIG['mysql_user'], (11) $database_name, or (12) $sqlfile variable.

    Source:Larry W. Cashdollar
    Published:10 Jun 2015
    6.4
    Medium

    CVE-2014-8598

    Last Modified: 8 Jun 2018

    The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page. NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code.

    Source:Metasploit
    Published:18 Nov 2014
    7.5
    High

    CVE-2014-8596

    Last Modified: 10 Nov 2014

    Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.

    Source:XLabs Security
    Published:17 Nov 2014
    7.5
    High

    CVE-2014-8586

    Last Modified: 27 Oct 2014

    SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.

    Source:Claudio Viviani
    Published:4 Nov 2014
    4.3
    Medium

    CVE-2014-8577

    Last Modified: 14 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter to admin/contacts/contacts/add page; (2) data[Block][title] or (3) data[Block][alias] parameter to admin/blocks/blocks/edit page; (4) data[Region][title] parameter to admin/blocks/regions/add page; (5) data[Menu][title] or (6) data[Menu][alias] parameter to admin/menus/menus/add page; or (7) data[Link][title] parameter to admin/menus/links/add/menu page.

    Source:LiquidWorm
    Published:31 Oct 2014
    5
    Medium

    CVE-2014-8555

    Last Modified: 7 Nov 2014

    Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the selection parameter.

    Source:XLabs Security
    Published:12 Nov 2014
    7.5
    High

    CVE-2014-8517

    Last Modified: 15 Dec 2014

    The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.

    Source:dash
    Published:17 Nov 2014
    9.8
    Critical

    CVE-2014-8516

    Last Modified: 10 Nov 2014

    Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Source:Metasploit
    Published:3 Jan 2020
    7.5
    High

    CVE-2014-8507

    Last Modified: 26 Nov 2014

    Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135.

    Source:Baidu X-Team
    Published:15 Dec 2014
    6.5
    Medium

    CVE-2014-8499

    Last Modified: 25 Jan 2018

    Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.

    Source:Pedro Ribeiro
    Published:17 Nov 2014