Latest CVE Feed
-
5.5
MEDIUMCVE-2014-4659
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.... Read more
Affected Products : ansible- EPSS Score: %0.08
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-4658
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.... Read more
Affected Products : ansible- EPSS Score: %0.12
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4657
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.... Read more
Affected Products : ansible- EPSS Score: %2.24
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4651
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.... Read more
Affected Products : jclouds- EPSS Score: %2.09
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4650
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code... Read more
- EPSS Score: %14.86
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.... Read more
Affected Products : piwigo- EPSS Score: %4.03
- Published: Mar. 16, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4612
Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : coppermine_photo_gallery- EPSS Score: %0.56
- Published: Mar. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-4610
Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted L... Read more
Affected Products : ffmpeg- EPSS Score: %2.98
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-4609
Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.... Read more
Affected Products : libav- EPSS Score: %2.15
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-4607
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.... Read more
- EPSS Score: %6.28
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4592
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : wp-planet- EPSS Score: %3.80
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4567
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message p... Read more
Affected Products : video_comments_webcam_recorder- EPSS Score: %0.22
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4561
The ultimate-weather plugin 1.0 for WordPress has XSS... Read more
Affected Products : ultimate-weather- EPSS Score: %12.80
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4559
Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, ... Read more
Affected Products : swipehq-payment-gateway-wp-e-commerce- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4558
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.... Read more
Affected Products : swipehq-payment-gateway-woocommerce- EPSS Score: %10.64
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4553
Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : spreadshirt-rss-3d-cube-flash-gallery- EPSS Score: %0.17
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4550
Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.... Read more
Affected Products : ninja- EPSS Score: %2.71
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4548
Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the popup parameter.... Read more
Affected Products : ruven-toolkit- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4544
Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php.... Read more
Affected Products : podcast_channels- EPSS Score: %2.58
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4539
Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.... Read more
Affected Products : movies- EPSS Score: %1.61
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024