Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2014-1214

    views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and (2) arbitrary extension in the Filename parameter.... Read more

    Affected Products : smart_flash_header
    • EPSS Score: %4.10
    • Published: Nov. 13, 2019
    • Modified: Nov. 21, 2024
  • 4.0

    MEDIUM
    CVE-2014-125111

    A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version... Read more

    Affected Products : wp-insert
    • Published: Apr. 08, 2024
    • Modified: Nov. 21, 2024
  • 4.0

    MEDIUM
    CVE-2014-125110

    A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross si... Read more

    Affected Products : wordpress_file_upload
    • Published: Apr. 01, 2024
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125109

    A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email lea... Read more

    Affected Products : portfolio
    • EPSS Score: %0.07
    • Published: Dec. 26, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125108

    A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The manipulation leads to cross site scripting. The attack may be initiated remo... Read more

    Affected Products : spell_checker
    • EPSS Score: %0.08
    • Published: Dec. 23, 2023
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2014-125107

    A vulnerability was found in Corveda PHPSandbox 1.3.4 and classified as critical. Affected by this issue is some unknown functionality of the component String Handler. The manipulation leads to protection mechanism failure. The attack may be launched remo... Read more

    Affected Products : phpsandbox
    • EPSS Score: %0.08
    • Published: Dec. 19, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125105

    A vulnerability was found in Broken Link Checker Plugin up to 1.10.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function options_page of the file core/core.php of the component Settings Page. The manipulation ... Read more

    • EPSS Score: %0.06
    • Published: Jun. 05, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-125104

    A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the function protect_aioseo_ajax of the file class.vaultpress-hotfixes.php of the component MailPoet Plugin. The m... Read more

    Affected Products : vaultpress
    • EPSS Score: %0.06
    • Published: Jun. 01, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125103

    A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function twttr_settings_page of the file twitter.php. The manipulation of the argument twttr_url_t... Read more

    Affected Products : twitter
    • EPSS Score: %0.07
    • Published: May. 31, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-125102

    A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the component Thumbnail Handler. The manipulation leads to information disclosure. T... Read more

    Affected Products : relevant
    • EPSS Score: %0.08
    • Published: May. 29, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-125101

    A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 i... Read more

    Affected Products : portfolio_gallery
    • EPSS Score: %0.10
    • Published: May. 28, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125100

    A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0... Read more

    Affected Products : job_board
    • EPSS Score: %0.08
    • Published: May. 02, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-125099

    A vulnerability has been found in I Recommend This Plugin up to 3.7.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the file dot-irecommendthis.php. The manipulation leads to sql injection. The atta... Read more

    Affected Products : i_recommend_this
    • EPSS Score: %0.10
    • Published: Apr. 20, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125098

    A vulnerability was found in Dart http_server up to 0.9.5 and classified as problematic. Affected by this issue is the function VirtualDirectory of the file lib/src/virtual_directory.dart of the component Directory Listing Handler. The manipulation of the... Read more

    Affected Products : http_server
    • EPSS Score: %0.07
    • Published: Apr. 10, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125097

    A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is p... Read more

    Affected Products : facebook_button
    • EPSS Score: %0.06
    • Published: Apr. 10, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125096

    A vulnerability was found in Fancy Gallery Plugin 1.5.12 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file class.options.php of the component Options Page. The manipulation leads to c... Read more

    Affected Products : fancy_gallery
    • EPSS Score: %0.09
    • Published: Apr. 10, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125095

    A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email ... Read more

    Affected Products : contact_form
    • EPSS Score: %0.08
    • Published: Apr. 09, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125094

    A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9... Read more

    Affected Products : phpminiadmin
    • EPSS Score: %0.06
    • Published: Apr. 06, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2014-125093

    A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads to information disclosure. The attac... Read more

    Affected Products : ad_blocking_detector
    • EPSS Score: %0.26
    • Published: Mar. 10, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2014-125092

    A vulnerability was found in MaxButtons Plugin up to 1.26.0 on WordPress and classified as problematic. This issue affects the function maxbuttons_strip_px of the file includes/maxbuttons-button.php. The manipulation of the argument button_id leads to cro... Read more

    Affected Products : maxbuttons
    • EPSS Score: %0.07
    • Published: Mar. 05, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 291806 Results