|
282521
|
9.8 |
CRITICAL
Network
|
themeist
|
i_recommend_this
|
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
|
CWE-89
SQL Injection
|
CVE-2014-10376
|
2024-11-21 11:03 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282522
|
7.5 |
HIGH
Network
|
gnu
|
exosip
|
handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
|
CWE-189
Numeric Errors
|
CVE-2014-10375
|
2024-11-21 11:03 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282523
|
6.5 |
MEDIUM
Adjacent
|
fitbit
|
charge_2_firmware
|
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without …
|
CWE-200
Information Exposure
|
CVE-2014-10374
|
2024-11-21 11:03 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282524
|
5.3 |
MEDIUM
Network
|
vembu
|
storegrid
|
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect…
|
CWE-200
Information Exposure
|
CVE-2014-10079
|
2024-11-21 11:03 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282525
|
6.1 |
MEDIUM
Network
|
vembu
|
storegrid
|
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registe…
|
CWE-79
Cross-site Scripting
|
CVE-2014-10078
|
2024-11-21 11:03 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282526
|
7.5 |
HIGH
Network
|
i18n_project debian
|
i18n debian_linux
|
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is pre…
|
CWE-20
Improper Input Validation
|
CVE-2014-10077
|
2024-11-21 11:03 |
2018-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282527
|
7.5 |
HIGH
Network
|
wp-db-backup_project
|
wp-db-backup
|
The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
|
CWE-200
Information Exposure
|
CVE-2014-10076
|
2024-11-21 11:03 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282528
|
9.8 |
CRITICAL
Network
|
karo_project
|
karo
|
The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
|
CWE-77
Command Injection
|
CVE-2014-10075
|
2024-11-21 11:03 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282529
|
9.8 |
CRITICAL
Network
|
umbraco
|
umbraco_cms
|
Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-10074
|
2024-11-21 11:03 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282530
|
7.5 |
HIGH
Network
|
fancy-server_project
|
fancy-server
|
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.
|
CWE-22
Path Traversal
|
CVE-2014-10066
|
2024-11-21 11:03 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|