Latest CVE Feed
-
4.3
MEDIUMCVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.... Read more
Affected Products : wpmarketplace- EPSS Score: %5.25
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-9013
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_i... Read more
Affected Products : wpmarketplace- EPSS Score: %36.69
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
7.6
HIGHCVE-2014-8985
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810... Read more
Affected Products : internet_explorer- EPSS Score: %12.57
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8945
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.... Read more
Affected Products : lexiglot- EPSS Score: %17.76
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-8944
Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config install_name, intro_message, or new_file_content parameter.... Read more
Affected Products : lexiglot- EPSS Score: %0.21
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-8943
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.... Read more
Affected Products : lexiglot- EPSS Score: %0.31
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGH- EPSS Score: %0.14
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8941
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.... Read more
Affected Products : lexiglot- EPSS Score: %0.26
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-8940
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.... Read more
Affected Products : lexiglot- EPSS Score: %0.24
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-8939
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages.... Read more
Affected Products : lexiglot- EPSS Score: %0.20
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8938
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.... Read more
Affected Products : lexiglot- EPSS Score: %0.05
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-8937
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.... Read more
Affected Products : lexiglot- EPSS Score: %0.33
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-8888
The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via vectors related to an "HTTP command injection issue."... Read more
- EPSS Score: %8.47
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-8780
Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script or HTML via a content section note.... Read more
Affected Products : jease- EPSS Score: %0.14
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8742
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : markvision_enterprise- EPSS Score: %8.10
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-8741
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.... Read more
Affected Products : markvision_enterprise- EPSS Score: %70.35
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for ... Read more
- EPSS Score: %78.94
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-8674
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary cod... Read more
Affected Products : soplanning- EPSS Score: %0.66
- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8673
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.... Read more
Affected Products : soplanning- EPSS Score: %49.86
- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8650
python-requests-Kerberos through 0.5 does not handle mutual authentication... Read more
- EPSS Score: %0.48
- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024