Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.9

    MEDIUM
    CVE-2014-2031

    Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwoo... Read more

    Affected Products : maradns deadwood
    • EPSS Score: %0.73
    • Published: Mar. 20, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2014-2030

    Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld stri... Read more

    Affected Products : ubuntu_linux imagemagick opensuse
    • EPSS Score: %20.77
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-2025

    Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an... Read more

    Affected Products : intrexx
    • EPSS Score: %9.01
    • Published: Jan. 31, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-2017

    CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arb... Read more

    Affected Products : eshop
    • EPSS Score: %2.19
    • Published: Jan. 18, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2014-1958

    Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.... Read more

    Affected Products : ubuntu_linux imagemagick opensuse
    • EPSS Score: %1.30
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2014-1947

    Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involv... Read more

    • EPSS Score: %6.95
    • Published: Feb. 17, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2014-1946

    OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.... Read more

    Affected Products : opendocman
    • EPSS Score: %0.83
    • Published: Apr. 10, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2014-1938

    python-rply before 0.7.4 insecurely creates temporary files.... Read more

    Affected Products : rply
    • EPSS Score: %0.14
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-1937

    Gamera before 3.4.1 insecurely creates temporary files.... Read more

    Affected Products : gamera
    • EPSS Score: %0.42
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-1936

    rc before 1.7.1-5 insecurely creates temporary files.... Read more

    Affected Products : debian_linux rc
    • EPSS Score: %0.43
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2014-1935

    9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.... Read more

    Affected Products : debian_linux 9base
    • EPSS Score: %0.47
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-1925

    SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote authenticated users to execute arbitrar... Read more

    Affected Products : koha
    • EPSS Score: %2.52
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-1924

    The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not require authentication, which allows remote attackers to conduct SQL inject... Read more

    Affected Products : koha
    • EPSS Score: %4.08
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-1923

    Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to a... Read more

    Affected Products : koha
    • EPSS Score: %2.42
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-1922

    Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.... Read more

    Affected Products : koha
    • EPSS Score: %0.92
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2014-1889

    The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.... Read more

    Affected Products : buddypress
    • EPSS Score: %11.75
    • Published: Apr. 10, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2014-1867

    suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution... Read more

    Affected Products : suphp
    • EPSS Score: %0.06
    • Published: Dec. 13, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-1860

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities... Read more

    Affected Products : contao contao_cms
    • EPSS Score: %0.28
    • Published: Jan. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2014-1859

    (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.... Read more

    Affected Products : enterprise_linux fedora numpy
    • EPSS Score: %0.07
    • Published: Jan. 08, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2014-1858

    __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.... Read more

    Affected Products : numpy
    • EPSS Score: %0.07
    • Published: Jan. 08, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291812 Results