Latest CVE Feed
-
8.8
HIGHCVE-2014-4607
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.... Read more
- EPSS Score: %6.28
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4592
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : wp-planet- EPSS Score: %3.80
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4567
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message p... Read more
Affected Products : video_comments_webcam_recorder- EPSS Score: %0.22
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4561
The ultimate-weather plugin 1.0 for WordPress has XSS... Read more
Affected Products : ultimate-weather- EPSS Score: %12.80
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4559
Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, ... Read more
Affected Products : swipehq-payment-gateway-wp-e-commerce- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4558
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.... Read more
Affected Products : swipehq-payment-gateway-woocommerce- EPSS Score: %10.64
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4553
Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : spreadshirt-rss-3d-cube-flash-gallery- EPSS Score: %0.17
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4550
Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.... Read more
Affected Products : ninja- EPSS Score: %2.71
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4548
Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the popup parameter.... Read more
Affected Products : ruven-toolkit- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4544
Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php.... Read more
Affected Products : podcast_channels- EPSS Score: %2.58
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4539
Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.... Read more
Affected Products : movies- EPSS Score: %1.61
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4536
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2... Read more
Affected Products : infusionsoft_gravity_forms- EPSS Score: %2.65
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4535
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.... Read more
Affected Products : import_legacy_media- EPSS Score: %3.80
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.19
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4525
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.... Read more
Affected Products : wp_ebay_product_feeds- EPSS Score: %0.22
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4523
Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : easy_career_openings- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4519
Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the 'page' parameter.... Read more
Affected Products : conversador- EPSS Score: %0.24
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2014-4198
A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.... Read more
Affected Products : rbs_bs-client._retail_client- EPSS Score: %0.28
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-4196
Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attackers to inject arbitrary web script or HTML via the colorstyle parameter.... Read more
Affected Products : rbs_bs-client- EPSS Score: %0.22
- Published: Jan. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4172
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary w... Read more
- EPSS Score: %6.74
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024