|
289931
|
6.1 |
MEDIUM
Network
|
cformsii_project
|
cformsii
|
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-10377
|
2024-11-21 11:03 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289932
|
6.1 |
MEDIUM
Network
|
cozmoslabs
|
profile_builder
|
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
|
CWE-79
Cross-site Scripting
|
CVE-2014-10380
|
2024-11-21 11:03 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289933
|
8.8 |
HIGH
Network
|
user_domain_whitelist_project
|
user_domain_whitelist
|
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2014-10381
|
2024-11-21 11:03 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289934
|
9.8 |
CRITICAL
Network
|
themeist
|
i_recommend_this
|
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
|
CWE-89
SQL Injection
|
CVE-2014-10376
|
2024-11-21 11:03 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289935
|
7.5 |
HIGH
Network
|
gnu
|
exosip
|
handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
|
CWE-189
Numeric Errors
|
CVE-2014-10375
|
2024-11-21 11:03 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289936
|
6.5 |
MEDIUM
Adjacent
|
fitbit
|
charge_2_firmware
|
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without …
|
CWE-200
Information Exposure
|
CVE-2014-10374
|
2024-11-21 11:03 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289937
|
5.3 |
MEDIUM
Network
|
vembu
|
storegrid
|
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect…
|
CWE-200
Information Exposure
|
CVE-2014-10079
|
2024-11-21 11:03 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289938
|
6.1 |
MEDIUM
Network
|
vembu
|
storegrid
|
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registe…
|
CWE-79
Cross-site Scripting
|
CVE-2014-10078
|
2024-11-21 11:03 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289939
|
7.5 |
HIGH
Network
|
i18n_project debian
|
i18n debian_linux
|
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is pre…
|
CWE-20
Improper Input Validation
|
CVE-2014-10077
|
2024-11-21 11:03 |
2018-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289940
|
7.5 |
HIGH
Network
|
wp-db-backup_project
|
wp-db-backup
|
The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
|
CWE-200
Information Exposure
|
CVE-2014-10076
|
2024-11-21 11:03 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|