Latest CVE Feed
-
5.0
MEDIUMCVE-2014-9119
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.... Read more
Affected Products : db_backup- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8145
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.... Read more
- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8144
Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a user OAuth authorization code via unknown vectors.... Read more
Affected Products : doorkeeper- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2011-5284
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perfor... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action.... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9401
Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks vi... Read more
Affected Products : wp_limit_posts_automatically- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9400
Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp Unique Article Header Image plugin 1.0 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS... Read more
Affected Products : wp_unique_article_header_image- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9399
Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the tweetscribe... Read more
Affected Products : tweetscribe- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9398
Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the mash... Read more
Affected Products : twitter_liveblog- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9397
Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the message_format parameter in th... Read more
Affected Products : twimp-wp- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9396
Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleFlickr plugin 3.0.3 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via th... Read more
Affected Products : simpleflickr- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9395
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simplelife plugin 1.2 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1... Read more
Affected Products : simplelife- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9394
Multiple cross-site request forgery (CSRF) vulnerabilities in the PWGRandom plugin 1.11 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1... Read more
Affected Products : pwgrandom- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9393
Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via t... Read more
Affected Products : post_to_twitter- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9392
Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) a... Read more
Affected Products : pictobrowser- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9391
Multiple cross-site request forgery (CSRF) vulnerabilities in the gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1... Read more
Affected Products : gslideshow- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9367
Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a "'" (single quote) in the scope parameter to do/view/TWiki/WebSearch.... Read more
Affected Products : twiki- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9325
Multiple cross-site scripting (XSS) vulnerabilities in TWiki 6.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERYSTRING variable in lib/TWiki.pm or (2) QUERYPARAMSTRING variable in lib/TWiki/UI/View.pm, as demonstrated by ... Read more
Affected Products : twiki- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9254
bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.... Read more
Affected Products : minibb- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8752
Multiple cross-site scripting (XSS) vulnerabilities in view.php in JCE-Tech PHP Video Script (aka Video Niche Script) 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) video or (2) title parameter.... Read more
Affected Products : video_niche_script- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025