Latest CVE Feed
-
6.8
MEDIUMCVE-2014-8104
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9220
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-9141
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.... Read more
Affected Products : fixed_assets_cs- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3988
Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file.... Read more
Affected Products : kcfinder- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9184
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.... Read more
Affected Products : zxdsl- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-9183
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.... Read more
Affected Products : zxdsl- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9182
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.... Read more
Affected Products : anchor_cms- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9181
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot do... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9180
Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING.... Read more
Affected Products : eleanor_cms- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9179
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.... Read more
Affected Products : supportezzy_ticket_system- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9178
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) v... Read more
Affected Products : sp_project_\&_document_manager- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9177
The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php.... Read more
Affected Products : html5_mp3_player_with_playlist_free- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9176
Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php.... Read more
Affected Products : sexy_squeeze_pages- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9175
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.... Read more
Affected Products : wpdatatables- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9174
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_co... Read more
Affected Products : google_analytics- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9173
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9116
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer o... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService ser... Read more
Affected Products : prosystem_fx_engagement- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9112
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8874
The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remote attackers to obtain sensitive information via a direct request.... Read more
Affected Products : ke_questionnaire- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025