Latest CVE Feed
-
10.0
HIGHCVE-2014-8423
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.... Read more
Affected Products : vap2500_firmware- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7850
Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-7178
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.... Read more
Affected Products : tuleap- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6075
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by re... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4883
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning ... Read more
Affected Products : lwip- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4832
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during a... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2014-4831
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-4829
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authe... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3407
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via cr... Read more
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-5426
MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled exception and DNP3 process crash) via a crafted message.... Read more
- Published: Nov. 27, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9104
Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting establ... Read more
Affected Products : openvpn_access_server- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9103
Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of an array parameter or the filename parameter in the Content-Dispo... Read more
Affected Products : kunena- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-9102
Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array parameter, as demonstrated by the topics[] parameter in an unfavorit... Read more
Affected Products : kunena- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9101
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) a... Read more
- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9100
Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the idcode parameter in the whydowork_adsense page to wp-admin/options-general.php.... Read more
Affected Products : whydowork_adsense- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9099
Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page ... Read more
Affected Products : whydowork_adsense- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-9098
Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoads... Read more
Affected Products : contus_video_gallery- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9097
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in ... Read more
Affected Products : contus_video_gallery- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9096
Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.... Read more
Affected Products : pligg_cms- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9095
Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records.... Read more
Affected Products : power_iq- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025