Latest CVE Feed
-
5.4
MEDIUMCVE-2014-6685
The Tsushima Travel Guide (aka com.netjapan.ntsushima) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : tsushima_travel_guide- Published: Sep. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6695
The Wedding Photo Frames-Love Pics (aka com.WeddingPhotoFramesLovePics) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craft... Read more
Affected Products : wedding_photo_frames-love_pics- Published: Sep. 24, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6709
The TechRadar News (aka com.techradar.news) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : techradar_news- Published: Sep. 25, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6713
The MedQuiz: Medical Chat and MCQs (aka com.pdevsmedd.med) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : _medical_chat_and_mcqs_project- Published: Sep. 25, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6725
The SchoolXM (aka apprentice.schoolxm) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : schoolxm- Published: Sep. 26, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6736
The EPL Hat Trick (aka com.hat.trick.goal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : epl_hat_trick- Published: Sep. 27, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6741
The John MacArthur (aka com.john.macarthur) application 1.0.26 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : john_macarthur- Published: Sep. 27, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-37207
Missing Authorization vulnerability in Theme4Press Demo Awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Awesome: from n/a through 1.0.2.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2014-6854
The EyeXam (aka com.globaleyeventures.eyexam) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : eyexam- Published: Oct. 01, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6861
The Terrarienbilder.com Forum (aka com.tapatalk.terrarienbildercomvb) application 3.8.20 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craf... Read more
Affected Products : terrarienbilder.com_forum- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6865
The Jamal Bates Show (aka com.conduit.app_3a95e13827c54c4da9056fafb33ecc8d.app) application 1.3.14.254 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat... Read more
Affected Products : jamal_bates_show- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7994
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the ... Read more
Affected Products : meraki_mx_firmware meraki_mr_firmware meraki_ms_firmware meraki_mr meraki_mx meraki_ms- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-0820
The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : jobs_for_wordpress- Published: Mar. 18, 2024
- Modified: Mar. 28, 2025
-
5.4
MEDIUMCVE-2024-0871
The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Widget 'fl_builder_data[node_preview][link]' and 'fl_builder_data[settings][link_target]' parameters in all versions up to, and including, 2.7.4.2 due to ins... Read more
- Published: Mar. 13, 2024
- Modified: Jan. 02, 2025
-
5.4
MEDIUMCVE-2025-24750
Missing Authorization vulnerability in ExactMetrics ExactMetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ExactMetrics: from n/a through 8.1.0.... Read more
Affected Products : exactmetrics- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2023-26954
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Group module.... Read more
- Published: Mar. 07, 2023
- Modified: Mar. 06, 2025
-
5.4
MEDIUMCVE-2014-6758
The Qin Story (aka com.kongzhong.tjmammoth.android.cqqslengp) application 1.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : qin_story- Published: Sep. 28, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-1849
The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL... Read more
Affected Products : wp_customer_reviews- Published: Apr. 15, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2014-6761
The Aprende a Meditar (aka com.rareartifact.aprendeameditar544CB0A2) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ... Read more
Affected Products : aprende_a_meditar- Published: Sep. 28, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-37125
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : seacms- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024