Latest CVE Feed
-
4.3
MEDIUMCVE-2014-3548
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger an AJA... Read more
Affected Products : moodle- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8377
Cross-site scripting (XSS) vulnerability in Webasyst Shop-Script 5.2.2.30933 allows remote attackers to inject arbitrary web script or HTML via the phone number field in a new contact to phpecom/index.php/webasyst/contacts/.... Read more
Affected Products : shop-script- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3542
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity referenc... Read more
Affected Products : moodle- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8469
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.... Read more
- Published: Nov. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8602
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.... Read more
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3543
mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via a package with a manifest file containing an XML external entity decla... Read more
Affected Products : moodle- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3529
The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.... Read more
Affected Products : poi- Published: Sep. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3653
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.... Read more
Affected Products : foreman- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9253
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/... Read more
- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8539
Cross-site scripting (XSS) vulnerability in Simple Email Form 1.8.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the mod_simpleemailform_field2_1 parameter to index.php.... Read more
Affected Products : simple_email_form- Published: Nov. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3502
Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.... Read more
Affected Products : cordova- Published: Nov. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8557
Multiple cross-site scripting (XSS) vulnerabilities in JExperts Channel Platform 5.0.33_CCB allow remote attackers to inject arbitrary web script or HTML via the (1) usuario.nome variable in an editarUsuario action to usuario.do or (2) titulo.form variabl... Read more
Affected Products : channel_platform- Published: Nov. 13, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8617
Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script o... Read more
Affected Products : fortimail- Published: Mar. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8593
Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.... Read more
Affected Products : allomani_weblinks- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8600
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) t... Read more
- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter to admin/contacts/contacts/add page; (2) data[Block][title] or (3) data[Blo... Read more
Affected Products : croogo- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3497
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.... Read more
Affected Products : swift- Published: Jul. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8584
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web-dorado_spider_video_player- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8629
Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.... Read more
- Published: Nov. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-0988
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-... Read more
- Published: Feb. 20, 2007
- Modified: Apr. 09, 2025