Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2014-1846

    Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.... Read more

    Affected Products : enlightenment
    • EPSS Score: %0.07
    • Published: Apr. 27, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2014-1845

    An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.... Read more

    Affected Products : enlightenment
    • EPSS Score: %0.06
    • Published: Apr. 27, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2014-1835

    The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.... Read more

    Affected Products : echor
    • EPSS Score: %0.05
    • Published: Feb. 02, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2014-1834

    The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.... Read more

    Affected Products : echor
    • EPSS Score: %0.12
    • Published: Feb. 02, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2014-1686

    MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.... Read more

    Affected Products : mediawiki
    • EPSS Score: %0.34
    • Published: Apr. 16, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2014-1665

    Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.... Read more

    Affected Products : owncloud
    • EPSS Score: %0.42
    • Published: Mar. 20, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2014-1634

    SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.... Read more

    Affected Products : advanced_newsletter
    • EPSS Score: %0.10
    • Published: Mar. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2014-1632

    htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.... Read more

    Affected Products : eventum
    • EPSS Score: %16.90
    • Published: Jan. 31, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-1631

    Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.... Read more

    Affected Products : eventum
    • EPSS Score: %27.60
    • Published: Jan. 31, 2018
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2014-1617

    Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of service.... Read more

    Affected Products : promotic
    • EPSS Score: %0.30
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2014-1598

    centurystar 7.12 ActiveX Control has a Stack Buffer Overflow... Read more

    Affected Products : centurystar
    • EPSS Score: %0.38
    • Published: Jan. 08, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2014-1457

    Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.... Read more

    Affected Products : open_web_analytics
    • EPSS Score: %0.03
    • Published: Mar. 20, 2018
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2014-1454

    Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input... Read more

    • EPSS Score: %0.18
    • Published: Jan. 08, 2020
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2014-1428

    A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.... Read more

    Affected Products : metal_as_a_service
    • EPSS Score: %0.24
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2014-1427

    A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.... Read more

    Affected Products : metal_as_a_service
    • EPSS Score: %0.38
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 8.6

    HIGH
    CVE-2014-1426

    A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9.2.... Read more

    Affected Products : metal_as_a_service
    • EPSS Score: %0.68
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2014-1423

    signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this crea... Read more

    Affected Products : signond ubuntu_touch
    • EPSS Score: %0.21
    • Published: May. 07, 2020
    • Modified: Nov. 21, 2024
  • 5.0

    MEDIUM
    CVE-2014-1422

    In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered by creation tim... Read more

    • EPSS Score: %0.04
    • Published: Jul. 22, 2020
    • Modified: Nov. 21, 2024
  • 3.8

    LOW
    CVE-2014-1420

    On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink at... Read more

    Affected Products : ubuntu-ui-toolkit
    • EPSS Score: %0.04
    • Published: Sep. 11, 2020
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2014-1409

    MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords... Read more

    Affected Products : sentry virtual_smartphone_platform
    • EPSS Score: %0.17
    • Published: Jan. 08, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291812 Results