Latest CVE Feed
-
6.8
MEDIUMCVE-2014-8773
MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter.... Read more
Affected Products : modx_revolution- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8772
Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticated users to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : x3_cms- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8771
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : x3_cms- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8104
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9220
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-9141
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.... Read more
Affected Products : fixed_assets_cs- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3988
Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file.... Read more
Affected Products : kcfinder- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9184
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.... Read more
Affected Products : zxdsl- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-9183
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.... Read more
Affected Products : zxdsl- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9182
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.... Read more
Affected Products : anchor_cms- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9181
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot do... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9180
Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING.... Read more
Affected Products : eleanor_cms- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9179
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.... Read more
Affected Products : supportezzy_ticket_system- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9178
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) v... Read more
Affected Products : sp_project_\&_document_manager- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9177
The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php.... Read more
Affected Products : html5_mp3_player_with_playlist_free- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9176
Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php.... Read more
Affected Products : sexy_squeeze_pages- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9175
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.... Read more
Affected Products : wpdatatables- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9174
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_co... Read more
Affected Products : google_analytics- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9173
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9116
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer o... Read more
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025