CVE-2014-9000 to CVE-2014-9999
155 CVEs with public proof-of-concept exploits.
- CVE-2014-90001 PoCMule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote…
- CVE-2014-90012 PoCsreminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell…
- CVE-2014-90042 PoCsCross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2014-90052 PoCsMultiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2014-90132 PoCsThe ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to…
- CVE-2014-90142 PoCsDirectory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for…
- CVE-2014-90162 PoCsThe password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal…
- CVE-2014-90171 PoCCross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 (build 23338) allows remote authenticated users to inject arbitrary web…
- CVE-2014-90311 PoCCross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3…
- CVE-2014-90321 PoCCross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows…
- CVE-2014-90331 PoCCross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to…
- CVE-2014-90344 PoCswp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote…
- CVE-2014-90351 PoCCross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before…
- CVE-2014-90361 PoCCross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows…
- CVE-2014-90371 PoCWordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an…
- CVE-2014-90381 PoCwp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to…
- CVE-2014-90391 PoCwp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset…
- CVE-2014-90942 PoCsMultiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin…
- CVE-2014-90951 PoCMultiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via…
- CVE-2014-90961 PoCMultiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL…
- CVE-2014-90972 PoCsMultiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed…
- CVE-2014-90981 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly…
- CVE-2014-90991 PoCCross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the…
- CVE-2014-91012 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow…
- CVE-2014-91121 PoCHeap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a…
- CVE-2014-91132 PoCsCCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and…
- CVE-2014-91151 PoCSQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and…
- CVE-2014-91182 PoCsThe web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell…
- CVE-2014-91192 PoCsDirectory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read…
- CVE-2014-91261 PoCMultiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arbitrary web…
- CVE-2014-91271 PoCOpen-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users…
- CVE-2014-91291 PoCCross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote…
- CVE-2014-91412 PoCsThe installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to…
- CVE-2014-91422 PoCsCross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary…
- CVE-2014-91432 PoCsOpen redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary…
- CVE-2014-91442 PoCsTechnicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2014-91451 PoCMultiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id…
- CVE-2014-91461 PoCMultiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2014-91472 PoCsFiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.
- CVE-2014-91482 PoCsFiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup…
- CVE-2014-91734 PoCsSQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute…
- CVE-2014-91752 PoCsSQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to…
- CVE-2014-91782 PoCsMultiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin…
- CVE-2014-91791 PoCCross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to…
- CVE-2014-91801 PoCOpen redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing…
- CVE-2014-91811 PoCMultiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a ..…
- CVE-2014-91952 PoCsPhoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
- CVE-2014-92081 PoCMultiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute…
- CVE-2014-92111 PoCClickDesk version 4.3 and below has persistent cross site scripting
- CVE-2014-92151 PoCSQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote…
- CVE-2014-92181 PoClibraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to…
- CVE-2014-92191 PoCCross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers…
- CVE-2014-92222 PoCsAllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to…
- CVE-2014-92241 PoCCross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec…
- CVE-2014-92251 PoCThe ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center…
- CVE-2014-92261 PoCThe management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced…
- CVE-2014-92351 PoCMultiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute…
- CVE-2014-92361 PoCCross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote…
- CVE-2014-92372 PoCsSQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element…
- CVE-2014-92391 PoCSQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board)…
- CVE-2014-92401 PoCSQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary…
- CVE-2014-92411 PoCMultiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject…
- CVE-2014-92421 PoCSQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2014-92431 PoCMultiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2014-92541 PoCbb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl…
- CVE-2014-92582 PoCsSQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL…
- CVE-2014-92602 PoCsThe basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every…
- CVE-2014-92612 PoCsThe sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote…
- CVE-2014-92621 PoCThe Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
- CVE-2014-92651 PoCStack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to…
- CVE-2014-93012 PoCsServer-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers…
- CVE-2014-93021 PoCServer-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in…
- CVE-2014-93031 PoCEntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and…
- CVE-2014-93041 PoCPlex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary…
- CVE-2014-93052 PoCsSQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for…
- CVE-2014-93084 PoCsUnrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping…
- CVE-2014-93111 PoCCross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remote authenticated…
- CVE-2014-93124 PoCsUnrestricted File Upload vulnerability in Photo Gallery 1.2.5.
- CVE-2014-93224 PoCsarch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS)…
- CVE-2014-93312 PoCsCross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to…
- CVE-2014-93441 PoCCross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of…
- CVE-2014-93452 PoCsSQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows remote attackers to…
- CVE-2014-93472 PoCsSQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2014-93482 PoCsSQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute…
- CVE-2014-93492 PoCsMultiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary…
- CVE-2014-93502 PoCsTP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a…
- CVE-2014-93822 PoCsFreebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
- CVE-2014-93901 PoCGit before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial…
- CVE-2014-94052 PoCsA Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface…
- CVE-2014-94101 PoCThe vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in…
- CVE-2014-94121 PoCMultiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject…
- CVE-2014-94151 PoCHuawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QES file.
- CVE-2014-94161 PoCMultiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute arbitrary code and…
- CVE-2014-94171 PoCThe Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a…
- CVE-2014-94181 PoCThe eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial…
- CVE-2014-94341 PoCCross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote…
- CVE-2014-94351 PoCMultiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the…
- CVE-2014-94362 PoCsAbsolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four…
- CVE-2014-94392 PoCsCross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or…
- CVE-2014-94402 PoCsSQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category…
- CVE-2014-94441 PoCCross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary…
- CVE-2014-94452 PoCsSQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL…
- CVE-2014-94485 PoCsBuffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or cause a denial of…
- CVE-2014-94562 PoCsBuffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an…
- CVE-2014-94572 PoCsSQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute…
- CVE-2014-94632 PoCsfunctions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP…
- CVE-2014-94641 PoCSQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL…
- CVE-2014-94711 PoCThe parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary…
- CVE-2014-94731 PoCUnrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to…
- CVE-2014-95162 PoCsCross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2014-95171 PoCCross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers to inject…
- CVE-2014-95222 PoCsMultiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web…
- CVE-2014-95282 PoCsSQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub…
- CVE-2014-95581 PoCMultiple SQL injection vulnerabilities in SmartCMS v.2.
- CVE-2014-95663 PoCsMultiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform…
- CVE-2014-95675 PoCsUnrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to…
- CVE-2014-95802 PoCsCross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or…
- CVE-2014-95812 PoCsDirectory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files…
- CVE-2014-95822 PoCsCross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary…
- CVE-2014-95834 PoCscommon.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and…
- CVE-2014-95971 PoCThe picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary…
- CVE-2014-95981 PoCThe picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or…
- CVE-2014-96051 PoCWebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and…
- CVE-2014-96061 PoCMultiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote…
- CVE-2014-96071 PoCCross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to…
- CVE-2014-96081 PoCCross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and…
- CVE-2014-96091 PoCDirectory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x…
- CVE-2014-96101 PoCNetsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP…
- CVE-2014-96111 PoCNetsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to…
- CVE-2014-96121 PoCSQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2…
- CVE-2014-96131 PoCMultiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2014-96141 PoCThe Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote…
- CVE-2014-96151 PoCCross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url…
- CVE-2014-96171 PoCOpen redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to…
- CVE-2014-96182 PoCsThe Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass…
- CVE-2014-96191 PoCUnrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9,…
- CVE-2014-96323 PoCsThe TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before…
- CVE-2014-96332 PoCsThe bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which…
- CVE-2014-96412 PoCsThe tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write…
- CVE-2014-96422 PoCsbdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows local users to write…
- CVE-2014-96432 PoCsK7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to…
- CVE-2014-96801 PoCsudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open…
- CVE-2014-97071 PoCEmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to…
- CVE-2014-97081 PoCEmbedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a…
- CVE-2014-97274 PoCsAVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
- CVE-2014-97343 PoCsDirectory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read…
- CVE-2014-97354 PoCsThe ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress…
- CVE-2014-97581 PoCCross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.
- CVE-2014-97721 PoCThe validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded…
- CVE-2014-99161 PoCMultiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2014-99171 PoCAn issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.
- CVE-2014-99181 PoCAn issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
- CVE-2014-99191 PoCAn issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
- CVE-2014-99381 PoCcontrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository…
- CVE-2014-99831 PoCDirectory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the…