Total
11061 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2014-8940 | 1 Piwigo | 1 Lexiglot | 2026-06-17 | 5.0 MEDIUM | 5.3 MEDIUM |
| Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI. | |||||
| CVE-2014-8923 | 1 Ibm | 2 Security Identity Manager Active Directory Adapter, Tivoli Identity Manager Active Directory Adapter | 2026-06-17 | 1.9 LOW | N/A |
| The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file. | |||||
| CVE-2014-8921 | 1 Ibm | 1 Notes Traveler Companion | 2026-06-17 | 4.3 MEDIUM | N/A |
| The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message. | |||||
| CVE-2014-8889 | 1 Dropbox | 1 Dropbox Sdk | 2026-06-17 | 2.6 LOW | 5.3 MEDIUM |
| Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack. | |||||
| CVE-2014-8874 | 1 Kennziffer | 1 Ke Questionnaire | 2026-06-17 | 5.0 MEDIUM | N/A |
| The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remote attackers to obtain sensitive information via a direct request. | |||||
| CVE-2014-8839 | 1 Apple | 1 Mac Os X | 2026-06-17 | 5.0 MEDIUM | N/A |
| Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL. | |||||
| CVE-2014-8834 | 1 Apple | 1 Mac Os X | 2026-06-17 | 2.1 LOW | N/A |
| UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, which allows local users to obtain sensitive information by reading a file. | |||||
| CVE-2014-8832 | 1 Apple | 1 Mac Os X | 2026-06-17 | 4.9 MEDIUM | N/A |
| The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive. | |||||
| CVE-2014-8788 | 1 Gleamtech | 1 Filevista | 2026-06-17 | 4.0 MEDIUM | N/A |
| GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in an error message. | |||||
| CVE-2014-8775 | 1 Modx | 1 Modx Revolution | 2026-06-17 | 5.0 MEDIUM | N/A |
| MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |||||
| CVE-2014-8762 | 1 Dokuwiki | 1 Dokuwiki | 2026-06-17 | 5.0 MEDIUM | N/A |
| The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter. | |||||
| CVE-2014-8761 | 1 Dokuwiki | 1 Dokuwiki | 2026-06-17 | 5.0 MEDIUM | N/A |
| inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call. | |||||
| CVE-2014-8736 | 1 Open Atrium Project | 1 Open Atrium | 2026-06-17 | 5.0 MEDIUM | N/A |
| The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node. | |||||
| CVE-2014-8735 | 1 Bad Behavior Project | 1 Bad Behavior | 2026-06-17 | 4.0 MEDIUM | N/A |
| The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords, which allows remote authenticated users with the "administer bad behavior" permission to obtain sensitive information by reading a log file. | |||||
| CVE-2014-8733 | 1 Cloudera | 1 Cloudera Manager | 2026-06-17 | 2.1 LOW | N/A |
| Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password. | |||||
| CVE-2014-8723 | 1 Get-simple | 1 Getsimple Cms | 2026-06-17 | 5.0 MEDIUM | 5.3 MEDIUM |
| GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message. | |||||
| CVE-2014-8722 | 1 Get-simple | 1 Getsimple Cms | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml. | |||||
| CVE-2014-8709 | 1 Linux | 1 Linux Kernel | 2026-06-17 | 5.0 MEDIUM | N/A |
| The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets. | |||||
| CVE-2014-8706 | 1 Pluck-cms | 1 Pluck | 2026-06-17 | 5.0 MEDIUM | 5.3 MEDIUM |
| Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message. | |||||
| CVE-2014-8702 | 1 Wondercms | 1 Wondercms | 2026-06-17 | 5.0 MEDIUM | 5.3 MEDIUM |
| Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message. | |||||
