|
279411
|
- |
|
digitalzoomstudio
|
video_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink …
|
CWE-79
Cross-site Scripting
|
CVE-2014-3923
|
2024-11-21 11:09 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279412
|
- |
|
trendmicro
|
interscan_messaging_security_virtual_appliance
|
Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows remote authenticated users to inject arbitrary web script or HTML via the addW…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3922
|
2024-11-21 11:09 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279413
|
- |
|
simple_popup_project
|
simple_popup
|
Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the z parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3921
|
2024-11-21 11:09 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279414
|
- |
|
dlink
|
dap-1350_firmware dap-1350
|
Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1…
|
CWE-89
SQL Injection
|
CVE-2014-3872
|
2024-11-21 11:09 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279415
|
- |
|
geodesicsolutions
|
geocore_max
|
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via t…
|
CWE-89
SQL Injection
|
CVE-2014-3871
|
2024-11-21 11:09 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279416
|
- |
|
bib2html_project
|
bib2html
|
Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the styleShortName parameter in an adminStyleAdd…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3870
|
2024-11-21 11:09 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279417
|
- |
|
usercake
|
usercake
|
Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that c…
|
CWE-352
Origin Validation Error
|
CVE-2014-3866
|
2024-11-21 11:09 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279418
|
- |
|
ibm
|
sametime
|
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote at…
|
CWE-200
Information Exposure
|
CVE-2014-3867
|
2024-11-21 11:09 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279419
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_aerogear
|
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with s…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3650
|
2024-11-21 11:08 |
2022-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279420
|
7.5 |
HIGH
Network
|
redhat
|
jboss_aerogear
|
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registere…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-3648
|
2024-11-21 11:08 |
2022-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|