|
277451
|
6.1 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9469
|
2024-11-21 11:20 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277452
|
8.8 |
HIGH
Network
|
10web
|
photo_gallery
|
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-9312
|
2024-11-21 11:20 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277453
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection.
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9411
|
2024-11-21 11:20 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277454
|
8.2 |
HIGH
Network
|
snapcreek
|
duplicator
|
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9262
|
2024-11-21 11:20 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277455
|
8.8 |
HIGH
Network
|
downloadmanager
|
download_manager
|
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9260
|
2024-11-21 11:20 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277456
|
6.1 |
MEDIUM
Network
|
wordpress_backup_to_dropbox_project
|
wordpress_backup_to_dropbox
|
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9310
|
2024-11-21 11:20 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277457
|
8.8 |
HIGH
Network
|
huawei
|
fusionmanager usg9500_firmware usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware
|
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with s…
|
CWE-352
Origin Validation Error
|
CVE-2014-9137
|
2024-11-21 11:20 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277458
|
8.8 |
HIGH
Network
|
huawei
|
fusionmanager usg9500_firmware usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware
|
Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
|
CWE-352
Origin Validation Error
|
CVE-2014-9136
|
2024-11-21 11:20 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277459
|
7.8 |
HIGH
Local
|
opensuse fedoraproject kernel
|
opensuse fedora util-linux
|
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
|
CWE-77
Command Injection
|
CVE-2014-9114
|
2024-11-21 11:20 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277460
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM…
|
CWE-20
Improper Input Validation
|
CVE-2014-9410
|
2024-11-21 11:20 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|