Search Results (91295 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-125070 1 Console Project 1 Console 2024-11-21 3.5 Low
A vulnerability has been found in yanheven console and classified as problematic. Affected by this vulnerability is the function get_zone_hosts/AvailabilityZonesTable of the file openstack_dashboard/dashboards/admin/aggregates/tables.py. The manipulation leads to cross site scripting. The attack can be launched remotely. The patch is named ba908ae88d5925f4f6783eb234cc4ea95017472b. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217651.
CVE-2014-125059 1 Sternenblog Project 1 Sternenblog 2024-11-21 5 Medium
A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects the function blog_index of the file main.c. The manipulation of the argument post_path leads to file inclusion. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 0.1.0 is able to address this issue. The identifier of the patch is cf715d911d8ce17969a7926dea651e930c27e71a. It is recommended to upgrade the affected component. The identifier VDB-217613 was assigned to this vulnerability. NOTE: This case is rather theoretical and probably won't happen. Maybe only on obscure Web servers.
CVE-2014-125044 1 Wing-tight Project 1 Wing-tight 2024-11-21 6.3 Medium
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. The patch is named 567bc33e6ed82b0d0179c9add707ac2b257aeaf2. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217515.
CVE-2014-125039 1 Neoxplora Project 1 Neoxplora 2024-11-21 3.5 Low
A vulnerability, which was classified as problematic, has been found in kkokko NeoXplora. Affected by this issue is some unknown functionality of the component Trainer Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is dce1aecd6ee050a29f953ffd8f02f21c7c13f1e6. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217352.
CVE-2014-125035 1 Jobs-plugin Project 1 Jobs-plugin 2024-11-21 3.5 Low
A vulnerability classified as problematic was found in Jobs-Plugin. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier of the patch is b8a56718b1d42834c6ec51d9c489c5dc20471d7b. It is recommended to apply a patch to fix this issue. The identifier VDB-217189 was assigned to this vulnerability.
CVE-2014-125034 1 Contact App Project 1 Contact App 2024-11-21 3.5 Low
A vulnerability has been found in stiiv contact_app and classified as problematic. Affected by this vulnerability is the function render of the file libs/View.php. The manipulation of the argument var leads to cross site scripting. The attack can be launched remotely. The patch is named 67bec33f559da9d41a1b45eb9e992bd8683a7f8c. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217183.
CVE-2014-125031 1 Teknet Project 1 Teknet 2024-11-21 3.5 Low
A vulnerability was found in kirill2485 TekNet. It has been classified as problematic. Affected is an unknown function of the file pages/loggedin.php. The manipulation of the argument statusentery leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 1c575340539f983333aa43fc58ecd76eb53e1816. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217176.
CVE-2014-10402 1 Perl 1 Dbi 2024-11-21 6.1 Medium
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
CVE-2014-10401 1 Perl 1 Dbi 2024-11-21 6.1 Medium
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
CVE-2014-10398 1 Bssys 1 Rbs Bs-client. Retail Client 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) DICTIONARY, (2) FILTERIDENT, (3) FROMSCHEME, (4) FromPoint, or (5) FName_0 parameter and a valid sid parameter value.
CVE-2014-10395 1 Codepeople 1 Polls Cp 2024-11-21 N/A
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2014-10394 1 Saschart 1 Rich Counter 2024-11-21 N/A
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
CVE-2014-10393 1 Cformsii Project 1 Cformsii 2024-11-21 N/A
The cforms2 plugin before 10.5 for WordPress has XSS.
CVE-2014-10392 1 Cformsii Project 1 Cformsii 2024-11-21 N/A
The cforms2 plugin before 10.2 for WordPress has XSS.
CVE-2014-10391 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2024-11-21 N/A
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVE-2014-10386 1 3cx 1 Live Chat 2024-11-21 N/A
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
CVE-2014-10385 1 Memphis Documents Library Project 1 Memphis Documents Library 2024-11-21 N/A
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
CVE-2014-10380 1 Cozmoslabs 1 Profile Builder 2024-11-21 N/A
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
CVE-2014-10378 1 Duplicate Post Project 1 Duplicate Post 2024-11-21 N/A
The duplicate-post plugin before 2.6 for WordPress has XSS.
CVE-2014-10377 1 Cformsii Project 1 Cformsii 2024-11-21 6.1 Medium
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.