|
285361
|
6.1 |
MEDIUM
Network
|
bssys
|
rbs_bs-client._retail_client
|
Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2014-10398
|
2024-11-21 11:03 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285362
|
6.1 |
MEDIUM
Network
|
ideagen
|
q-pulse
|
Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier.
|
CWE-79
Cross-site Scripting
|
CVE-2014-1238
|
2024-11-21 11:03 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285363
|
8.8 |
HIGH
Network
|
projoom
|
smart_flash_header
|
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-1214
|
2024-11-21 11:03 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285364
|
7.5 |
HIGH
Network
|
para
|
antioch
|
The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.
|
CWE-22
Path Traversal
|
CVE-2014-10397
|
2024-11-21 11:03 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285365
|
7.5 |
HIGH
Network
|
organizedthemes
|
epic
|
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
|
CWE-22
Path Traversal
|
CVE-2014-10396
|
2024-11-21 11:03 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285366
|
6.1 |
MEDIUM
Network
|
codepeople
|
polls_cp
|
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
|
CWE-79
Cross-site Scripting
|
CVE-2014-10395
|
2024-11-21 11:03 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285367
|
6.1 |
MEDIUM
Network
|
cformsii_project
|
cformsii
|
The cforms2 plugin before 10.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2014-10393
|
2024-11-21 11:03 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285368
|
6.1 |
MEDIUM
Network
|
3cx
|
live_chat
|
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
|
CWE-74
Injection
|
CVE-2014-10386
|
2024-11-21 11:03 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285369
|
4.3 |
MEDIUM
Network
|
pippinsplugins
|
featured_comments
|
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
|
CWE-352
Origin Validation Error
|
CVE-2014-10382
|
2024-11-21 11:03 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285370
|
6.1 |
MEDIUM
Network
|
saschart
|
rich_counter
|
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
|
CWE-74
Injection
|
CVE-2014-10394
|
2024-11-21 11:03 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|