Latest CVE Feed
-
5.3
MEDIUMCVE-2014-1935
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.... Read more
- EPSS Score: %0.47
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-1925
SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote authenticated users to execute arbitrar... Read more
Affected Products : koha- EPSS Score: %2.52
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-1924
The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not require authentication, which allows remote attackers to conduct SQL inject... Read more
Affected Products : koha- EPSS Score: %4.08
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-1923
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to a... Read more
Affected Products : koha- EPSS Score: %2.42
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-1922
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : koha- EPSS Score: %0.92
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-1889
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.... Read more
Affected Products : buddypress- EPSS Score: %11.75
- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-1867
suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution... Read more
Affected Products : suphp- EPSS Score: %0.06
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.28
- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-1859
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.... Read more
- EPSS Score: %0.07
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-1858
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : numpy- EPSS Score: %0.07
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-1846
Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.... Read more
Affected Products : enlightenment- EPSS Score: %0.07
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-1845
An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.... Read more
Affected Products : enlightenment- EPSS Score: %0.06
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-1835
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.... Read more
Affected Products : echor- EPSS Score: %0.05
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-1834
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.... Read more
Affected Products : echor- EPSS Score: %0.12
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-1686
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.... Read more
Affected Products : mediawiki- EPSS Score: %0.34
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-1665
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.... Read more
Affected Products : owncloud- EPSS Score: %0.42
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-1634
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.... Read more
Affected Products : advanced_newsletter- EPSS Score: %0.10
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2014-1632
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.... Read more
Affected Products : eventum- EPSS Score: %16.90
- Published: Jan. 31, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-1631
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.... Read more
Affected Products : eventum- EPSS Score: %27.60
- Published: Jan. 31, 2018
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2014-1617
Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of service.... Read more
Affected Products : promotic- EPSS Score: %0.30
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024