|
277091
|
9.8 |
CRITICAL
Network
|
airlive
|
bu-3026_firmware md-3025_firmware wl-2000cam_firmware poe-200cam_v2_firmware bu-2015_firmware
|
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with…
|
CWE-78
OS Command
|
CVE-2014-8389
|
2024-11-21 11:19 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277092
|
5.3 |
MEDIUM
Network
|
codeasily
|
grand_flagallery
|
The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-albu…
|
CWE-200
Information Exposure
|
CVE-2014-8491
|
2024-11-21 11:19 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277093
|
9.8 |
CRITICAL
Network
|
store_locator_project
|
store_locator
|
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
|
CWE-89
SQL Injection
|
CVE-2014-8621
|
2024-11-21 11:19 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277094
|
6.1 |
MEDIUM
Network
|
tech-banker
|
gallery_bank
|
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gall…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8758
|
2024-11-21 11:19 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277095
|
6.1 |
MEDIUM
Network
|
cozmoslabs
|
profile_builder
|
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2014-8492
|
2024-11-21 11:19 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277096
|
5.9 |
MEDIUM
Network
|
kde
|
kmail
|
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2014-8878
|
2024-11-21 11:19 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277097
|
5.3 |
MEDIUM
Network
|
dropbox
|
dropbox_sdk
|
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
|
CWE-200
Information Exposure
|
CVE-2014-8889
|
2024-11-21 11:19 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277098
|
9.8 |
CRITICAL
Network
|
codeigniter
|
codeigniter
|
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
|
CWE-310
Cryptographic Issues
|
CVE-2014-8686
|
2024-11-21 11:19 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277099
|
9.8 |
CRITICAL
Network
|
kohanaframework codeigniter
|
kohana codeigniter
|
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by lever…
|
CWE-310
Cryptographic Issues
|
CVE-2014-8684
|
2024-11-21 11:19 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277100
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create a…
|
CWE-94 CWE-284
Code Injection Improper Access Control
|
CVE-2014-8677
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|