Latest CVE Feed
-
10.0
HIGHCVE-2013-2810
Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack.... Read more
- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9304
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by ... Read more
- Published: Dec. 07, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-9303
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.... Read more
Affected Products : n5200_active_network_control_panel- Published: Dec. 07, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9302
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the... Read more
Affected Products : community_edition- Published: Dec. 07, 2014
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2014-9301
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in th... Read more
Affected Products : alfresco- Published: Dec. 07, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9300
Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that acc... Read more
Affected Products : alfresco- Published: Dec. 07, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-8868
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.... Read more
Affected Products : n5200_active_network_control_panel- Published: Dec. 07, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9117
MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a public_key parameter value, as demonstr... Read more
Affected Products : mantisbt- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-8651
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.... Read more
- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9278
The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intende... Read more
- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
3.2
LOWCVE-2014-7251
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.... Read more
Affected Products : fast\/tools- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-6140
IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies t... Read more
Affected Products : tivoli_endpoint_manager_mobile_device_management- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-5429
DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 build 141 and earlier, E3 1.0 through 4.6, and Elipse Power 1.0 through 4.6 allows remote attackers to cause a denial of service (CPU consumption) via malformed packets.... Read more
- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2014-4629
EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via unspecified vectors related to an insecure direct object reference.... Read more
Affected Products : documentum_content_server- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3099
Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to obtain sensitive information via unknown vectors.... Read more
Affected Products : systems_director- Published: Dec. 06, 2014
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2014-9292
Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.... Read more
Affected Products : jrss_widget- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-8877
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which ... Read more
Affected Products : cm_download_manager- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7259
SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application.... Read more
Affected Products : kaku_san_sei_million_aruthur- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7258
Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clip_board- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-7256
The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SEIL/x86 Fuji 1.00 through 3.22; SEIL/X1, SEIL/X2, and SEIL/B1 1.00 through 4.62; SEIL/Turbo 1.82 through 2.18; and SEIL/neu 2FE Plus 1.8... Read more
Affected Products : seil_x86_fuji_firmware seil_x2_firmware seil_b1_firmware seil_x1_firmware seil_plus_firmware seil_plus seil_turbo_firmware seil_turbo seil_b1 seil_x2 +2 more products- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025