|
279071
|
6.1 |
MEDIUM
Network
|
tech-banker
|
gallery_bank
|
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gall…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8758
|
2024-11-21 11:19 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279072
|
6.1 |
MEDIUM
Network
|
cozmoslabs
|
profile_builder
|
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2014-8492
|
2024-11-21 11:19 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279073
|
5.9 |
MEDIUM
Network
|
kde
|
kmail
|
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2014-8878
|
2024-11-21 11:19 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279074
|
5.3 |
MEDIUM
Network
|
dropbox
|
dropbox_sdk
|
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
|
CWE-200
Information Exposure
|
CVE-2014-8889
|
2024-11-21 11:19 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279075
|
9.8 |
CRITICAL
Network
|
codeigniter
|
codeigniter
|
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
|
CWE-310
Cryptographic Issues
|
CVE-2014-8686
|
2024-11-21 11:19 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279076
|
9.8 |
CRITICAL
Network
|
kohanaframework codeigniter
|
kohana codeigniter
|
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by lever…
|
CWE-310
Cryptographic Issues
|
CVE-2014-8684
|
2024-11-21 11:19 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279077
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create a…
|
CWE-94 CWE-284
Code Injection Improper Access Control
|
CVE-2014-8677
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279078
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL pa…
|
CWE-22
Path Traversal
|
CVE-2014-8676
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279079
|
7.5 |
HIGH
Network
|
soplanning
|
soplanning
|
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force at…
|
CWE-200
Information Exposure
|
CVE-2014-8675
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279080
|
7.8 |
HIGH
Local
|
avm
|
fritz\!box_6810_lte_firmware fritz\!box_6840_lte_firmware
|
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
|
CWE-94
Code Injection
|
CVE-2014-8872
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|