Search Results (82411 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-10395 1 Codepeople 1 Polls Cp 2024-11-21 N/A
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2014-10394 1 Saschart 1 Rich Counter 2024-11-21 N/A
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
CVE-2014-10393 1 Cformsii Project 1 Cformsii 2024-11-21 N/A
The cforms2 plugin before 10.5 for WordPress has XSS.
CVE-2014-10392 1 Cformsii Project 1 Cformsii 2024-11-21 N/A
The cforms2 plugin before 10.2 for WordPress has XSS.
CVE-2014-10391 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2024-11-21 N/A
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVE-2014-10386 1 3cx 1 Live Chat 2024-11-21 N/A
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
CVE-2014-10385 1 Memphis Documents Library Project 1 Memphis Documents Library 2024-11-21 N/A
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
CVE-2014-10380 1 Cozmoslabs 1 Profile Builder 2024-11-21 N/A
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
CVE-2014-10378 1 Duplicate Post Project 1 Duplicate Post 2024-11-21 N/A
The duplicate-post plugin before 2.6 for WordPress has XSS.
CVE-2014-10377 1 Cformsii Project 1 Cformsii 2024-11-21 6.1 Medium
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
CVE-2014-10078 1 Vembu 1 Storegrid 2024-11-21 N/A
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.
CVE-2014-10075 1 Karo Project 1 Karo 2024-11-21 N/A
The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
CVE-2014-10065 1 Remarkable Project 1 Remarkable 2024-11-21 N/A
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content.
CVE-2014-0883 1 Ibm 1 Power Hardware Management Console 2024-11-21 N/A
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  IBM X-Force ID:  91163.
CVE-2014-0593 1 Opensuse 1 Open Build Service 2024-11-21 N/A
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server.
CVE-2014-0241 2 Redhat, Theforeman 2 Satellite, Hammer Cli 2024-11-21 5.5 Medium
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
CVE-2014-0234 1 Redhat 1 Openshift 2024-11-21 9.8 Critical
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
CVE-2014-0183 1 Redhat 1 Subscription Asset Manager 2024-11-21 6.1 Medium
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
CVE-2014-0175 3 Debian, Puppet, Redhat 3 Debian Linux, Marionette Collective, Openshift 2024-11-21 9.8 Critical
mcollective has a default password set at install
CVE-2014-0163 1 Redhat 1 Openshift 2024-11-21 8.8 High
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.