Latest CVE Feed
-
6.1
MEDIUM- EPSS Score: %0.19
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4525
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.... Read more
Affected Products : wp_ebay_product_feeds- EPSS Score: %0.22
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4523
Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : easy_career_openings- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4519
Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the 'page' parameter.... Read more
Affected Products : conversador- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2014-4198
A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.... Read more
Affected Products : rbs_bs-client._retail_client- EPSS Score: %0.28
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4196
Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attackers to inject arbitrary web script or HTML via the colorstyle parameter.... Read more
Affected Products : rbs_bs-client- EPSS Score: %0.22
- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4172
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary w... Read more
- EPSS Score: %6.74
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4170
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.... Read more
Affected Products : articlefr- EPSS Score: %47.77
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-4156
Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability... Read more
Affected Products : virtual_environment- EPSS Score: %0.21
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-4150
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.... Read more
Affected Products : scheme48- EPSS Score: %0.06
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2014-4145
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810... Read more
Affected Products : internet_explorer- EPSS Score: %9.55
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2014-4112
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0304... Read more
Affected Products : internet_explorer- EPSS Score: %9.55
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2014-4066
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2787... Read more
Affected Products : internet_explorer- EPSS Score: %12.43
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-4024
SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accelerator... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_edge_gateway +3 more products- EPSS Score: %0.63
- Published: Mar. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-4019
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.... Read more
- EPSS Score: %59.44
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2014-3999
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.... Read more
Affected Products : horde_ldap- EPSS Score: %1.61
- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3990
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a cr... Read more
Affected Products : opencart- EPSS Score: %11.47
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3979
Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firewall to blacklist the IP.... Read more
Affected Products : symbiosis- EPSS Score: %1.99
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-3972
Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
- EPSS Score: %0.85
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2014-3919
A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.... Read more
- EPSS Score: %0.33
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024