|
280001
|
9.8 |
CRITICAL
Network
|
brookinsconsulting
|
collected_information_export
|
Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2552
|
2024-11-21 11:06 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280002
|
9.8 |
CRITICAL
Network
|
openwebanalytics
|
open_web_analytics
|
Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.
|
CWE-74
Injection
|
CVE-2014-2294
|
2024-11-21 11:06 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280003
|
5.9 |
MEDIUM
Network
|
oleumtech
|
ft1_firmware ad1_firmware
|
OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading cleartext protocol data.
|
CWE-200
Information Exposure
|
CVE-2014-2359
|
2024-11-21 11:06 |
2018-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280004
|
5.5 |
MEDIUM
Local
|
intel
|
thermald
|
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
|
CWE-59
Link Following
|
CVE-2014-2312
|
2024-11-21 11:06 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280005
|
9.8 |
CRITICAL
Network
|
zikula
|
zikula_application_framework
|
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data…
|
CWE-94
Code Injection
|
CVE-2014-2293
|
2024-11-21 11:06 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280006
|
6.5 |
MEDIUM
Network
|
wp-html-sitemap_project
|
wp-html-sitemap
|
Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for request…
|
CWE-352
Origin Validation Error
|
CVE-2014-2675
|
2024-11-21 11:06 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280007
|
7.5 |
HIGH
Network
|
ajax-pagination_project
|
ajax-pagination
|
Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_n…
|
CWE-22
Path Traversal
|
CVE-2014-2674
|
2024-11-21 11:06 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280008
|
9.8 |
CRITICAL
Network
|
unify
|
openscape_deployment_service
|
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-2652
|
2024-11-21 11:06 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280009
|
8.8 |
HIGH
Network
|
disable_comments
|
disable_comments_project
|
Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enab…
|
CWE-352
Origin Validation Error
|
CVE-2014-2550
|
2024-11-21 11:06 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280010
|
6.1 |
MEDIUM
Network
|
videowhisper
|
videowhisper_live_streaming_integration
|
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2297
|
2024-11-21 11:06 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|