Export limit exceeded: 89527 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (89527 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2014-10398 | 1 Bssys | 1 Rbs Bs-client. Retail Client | 2024-11-21 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) DICTIONARY, (2) FILTERIDENT, (3) FROMSCHEME, (4) FromPoint, or (5) FName_0 parameter and a valid sid parameter value. | ||||
| CVE-2014-10395 | 1 Codepeople | 1 Polls Cp | 2024-11-21 | N/A |
| The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. | ||||
| CVE-2014-10394 | 1 Saschart | 1 Rich Counter | 2024-11-21 | N/A |
| The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. | ||||
| CVE-2014-10393 | 1 Cformsii Project | 1 Cformsii | 2024-11-21 | N/A |
| The cforms2 plugin before 10.5 for WordPress has XSS. | ||||
| CVE-2014-10392 | 1 Cformsii Project | 1 Cformsii | 2024-11-21 | N/A |
| The cforms2 plugin before 10.2 for WordPress has XSS. | ||||
| CVE-2014-10391 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2024-11-21 | N/A |
| The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | ||||
| CVE-2014-10386 | 1 3cx | 1 Live Chat | 2024-11-21 | N/A |
| The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. | ||||
| CVE-2014-10385 | 1 Memphis Documents Library Project | 1 Memphis Documents Library | 2024-11-21 | N/A |
| The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST. | ||||
| CVE-2014-10380 | 1 Cozmoslabs | 1 Profile Builder | 2024-11-21 | N/A |
| The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. | ||||
| CVE-2014-10378 | 1 Duplicate Post Project | 1 Duplicate Post | 2024-11-21 | N/A |
| The duplicate-post plugin before 2.6 for WordPress has XSS. | ||||
| CVE-2014-10377 | 1 Cformsii Project | 1 Cformsii | 2024-11-21 | 6.1 Medium |
| The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. | ||||
| CVE-2014-10078 | 1 Vembu | 1 Storegrid | 2024-11-21 | N/A |
| Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php. | ||||
| CVE-2014-10075 | 1 Karo Project | 1 Karo | 2024-11-21 | N/A |
| The karo gem 2.3.8 for Ruby allows Remote command injection via the host field. | ||||
| CVE-2014-10065 | 1 Remarkable Project | 1 Remarkable | 2024-11-21 | N/A |
| Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content. | ||||
| CVE-2014-0883 | 1 Ibm | 1 Power Hardware Management Console | 2024-11-21 | N/A |
| IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163. | ||||
| CVE-2014-0593 | 1 Opensuse | 1 Open Build Service | 2024-11-21 | N/A |
| The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server. | ||||
| CVE-2014-0241 | 2 Redhat, Theforeman | 2 Satellite, Hammer Cli | 2024-11-21 | 5.5 Medium |
| rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable | ||||
| CVE-2014-0234 | 1 Redhat | 1 Openshift | 2024-11-21 | 9.8 Critical |
| The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281. | ||||
| CVE-2014-0183 | 1 Redhat | 1 Subscription Asset Manager | 2024-11-21 | 6.1 Medium |
| Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. | ||||
| CVE-2014-0175 | 3 Debian, Puppet, Redhat | 3 Debian Linux, Marionette Collective, Openshift | 2024-11-21 | 9.8 Critical |
| mcollective has a default password set at install | ||||