Latest CVE Feed
-
4.3
MEDIUMCVE-2014-7280
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.... Read more
Affected Products : web_ui- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-5006
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.... Read more
Affected Products : manageengine_desktop_central- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-5005
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.... Read more
Affected Products : manageengine_desktop_central- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-4577
Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.... Read more
Affected Products : wp_amasin_-_the_amazon_affiliate_shop- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4517
Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the searchString parameter.... Read more
Affected Products : cbi_referral_manager- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4514
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.... Read more
Affected Products : alipay- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-8375
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.... Read more
Affected Products : gb_gallery_slideshow- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7140
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.1-129.11 and 10.5 before 10.5-50.10 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : netscaler_application_delivery_controller_firmware- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-7406
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : mrbs- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5702
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) com... Read more
Affected Products : dotproject- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2012-5243
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.... Read more
Affected Products : banana_dance- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2012-5242
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.... Read more
Affected Products : banana_dance- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7804
The Gangsta Auto Thief III (aka com.apptreestudios.gdup3) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
Affected Products : gangsta_auto_thief_iii- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7803
The Woodward Bail (aka com.onesolutionapps.woodwardbailandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi... Read more
Affected Products : woodward_bail- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7802
The Top Roller Coasters Europe 2 (aka com.appaapps.top10tallesteuropeanrollercoasters2) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive i... Read more
Affected Products : top_roller_coasters_europe_2- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7800
The Daily Green (aka it.opentt.blog.dailygreen) application 2014.07 dlygrn for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : daily_green- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7799
The Squishy birds (aka com.tatmob.squishybirds) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : squishy_birds- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7798
The Coca-Cola FM Brasil (aka com.enyetech.radio.coca_cola.fm_br) application 2.0.41709 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte... Read more
Affected Products : coca-cola_fm_brasil- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7797
The Thai food (aka com.foods.thaifood) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : thai_food- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7796
The House365 Radio (aka com.nobexinc.wls_27853803.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : house365_radio- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025