Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-5665 1 Mr384 1 Mzone Login 2014-12-03 5.4 MEDIUM N/A
The Mzone Login (aka com.mr384.MzoneLogin) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5992 1 Successsecrets Project 1 Successsecrets 2014-12-03 5.4 MEDIUM N/A
The successsecrets (aka com.alek.successsecrets) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-5972 1 Loving.fm 1 Loving - Couple Essential 2014-12-03 5.4 MEDIUM N/A
The Loving - Couple Essential (aka com.xiaoenai.app) application 4.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-9179 1 Supportezzy Ticket System Project 1 Supportezzy Ticket System 2014-12-03 4.0 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.
CVE-2014-9184 1 Zte 1 Zxdsl 2014-12-03 5.0 MEDIUM N/A
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.
CVE-2014-9183 1 Zte 1 Zxdsl 2014-12-03 10.0 HIGH N/A
ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.
CVE-2014-9182 1 Anchorcms 1 Anchor Cms 2014-12-03 4.3 MEDIUM N/A
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
CVE-2014-3988 1 Sunhater 1 Kcfinder 2014-12-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file.
CVE-2014-5284 1 Ossec 1 Ossec 2014-12-02 7.2 HIGH N/A
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.
CVE-2013-6494 2 Fedoraproject, Fedup Project 2 Fedora, Fedup 2014-12-02 2.1 LOW N/A
fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).
CVE-2014-9156 1 Filefield Project 1 Filefield 2014-12-01 4.0 MEDIUM N/A
The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.
CVE-2014-9151 1 Services Project 1 Services 2014-12-01 7.5 HIGH N/A
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
CVE-2014-9153 1 Services Project 1 Services 2014-12-01 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response.
CVE-2014-9152 1 Services Project 1 Services 2014-12-01 7.5 HIGH N/A
The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
CVE-2014-5268 1 Fasttoggle Project 1 Fasttoggle 2014-12-01 5.8 MEDIUM N/A
The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link.
CVE-2014-8749 1 Ait-pro 1 Bulletproof Security 2014-12-01 5.0 MEDIUM N/A
Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.
CVE-2014-2233 1 Infoware 1 Mapsuite 2014-12-01 5.0 MEDIUM N/A
Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to trigger requests to intranet servers via unspecified vectors.
CVE-2014-8425 1 Arris 1 Vap2500 Firmware 2014-11-28 7.8 HIGH N/A
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
CVE-2014-8424 1 Arris 1 Vap2500 Firmware 2014-11-28 7.8 HIGH N/A
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
CVE-2014-8423 1 Arris 1 Vap2500 Firmware 2014-11-28 10.0 HIGH N/A
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.