Vulnerabilities (CVE)

Total 396876 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9270 1 Mantisbt 1 Mantisbt 2026-06-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the projax_array_serialize_for_autocomplete function in core/projax_api.php in MantisBT 1.1.0a3 through 1.2.17 allows remote attackers to inject arbitrary web script or HTML via the "profile/Platform" field.
CVE-2014-9269 2 Debian, Mantisbt 2 Debian Linux, Mantisbt 2026-06-17 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.
CVE-2014-9268 1 Autodesk 1 Design Review 2026-06-17 6.8 MEDIUM N/A
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
CVE-2014-9267 1 Ptc 1 Isoview 2026-06-17 6.8 MEDIUM N/A
Heap-based buffer overflow in the PTC IsoView ActiveX control allows remote attackers to execute arbitrary code via a crafted ViewPort property value.
CVE-2014-9266 1 Samsung 1 Smart Viewer 2026-06-17 6.8 MEDIUM N/A
The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2014-9265 1 Samsung 1 Smartviewer 2026-06-17 6.8 MEDIUM N/A
Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2014-9264 1 Sap 1 Sql Anywhere 2026-06-17 7.5 HIGH N/A
Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alias.
CVE-2014-9263 1 3s Pocketnet Tech 1 3s Pocketnet Tech Video Management Software 2026-06-17 6.8 MEDIUM N/A
Multiple buffer overflows in the PocketNetNVRMediaClientAxCtrl.NVRMediaViewer.1 control in 3S Pocketnet Tech VMS allow remote attackers to execute arbitrary code via a crafted string to the (1) StartRecord, (2) StartRecordEx, (3) StartScheduledRecord, (4) SetDisplayText, (5) GetONVIFDeviceInformation, (6) GetONVIFProfiles, or (7) GetONVIFStreamUri method or a crafted filename to the (8) SaveCurrentImage or (9) SaveCurrentImageEx method.
CVE-2014-9262 1 Snapcreek 1 Duplicator 2026-06-17 5.5 MEDIUM 8.2 HIGH
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
CVE-2014-9261 1 Codologic 1 Codoforum 2026-06-17 5.0 MEDIUM N/A
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
CVE-2014-9260 1 W3eden 1 Download Manager 2026-06-17 6.5 MEDIUM 8.8 HIGH
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
CVE-2014-9258 1 Glpi-project 1 Glpi 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.
CVE-2014-9254 1 Minibb 1 Minibb 2026-06-17 7.5 HIGH N/A
bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.
CVE-2014-9253 2 Dokuwiki, Mageia 2 Dokuwiki, Mageia 2026-06-17 4.3 MEDIUM N/A
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php.
CVE-2014-9252 1 Zenoss 1 Zenoss Core 2026-06-17 2.1 LOW N/A
Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416.
CVE-2014-9251 1 Zenoss 1 Zenoss Core 2026-06-17 5.0 MEDIUM N/A
Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack on hash values in the database, aka ZEN-15413.
CVE-2014-9250 1 Zenoss 1 Zenoss Core 2026-06-17 5.0 MEDIUM N/A
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418.
CVE-2014-9249 1 Zenoss 1 Zenoss Core 2026-06-17 7.5 HIGH N/A
The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open ports, aka ZEN-15408.
CVE-2014-9248 1 Zenoss 1 Zenoss Core 2026-06-17 5.0 MEDIUM N/A
Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-force attack, aka ZEN-15406.
CVE-2014-9247 1 Zenoss 1 Zenoss Core 2026-06-17 4.0 MEDIUM N/A
Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role information by visiting the ZenUsers (aka User Manager) page, aka ZEN-15389.