CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70149 | CVE-2014-2854 | Candidate | Cross-site scripting (XSS) vulnerability in the SemanticTitle extension before 1.1.0 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20140414) | None (candidate not yet proposed) | View | |
70405 | CVE-2014-3110 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input. | Assigned (20140429) | None (candidate not yet proposed) | View | |
70661 | CVE-2014-3365 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808. | Assigned (20140507) | None (candidate not yet proposed) | View | |
70917 | CVE-2014-3621 | Candidate | The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field. | Assigned (20140514) | None (candidate not yet proposed) | View | |
71173 | CVE-2014-3877 | Candidate | Incomplete blacklist vulnerability in Frams" Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup. | Assigned (20140527) | None (candidate not yet proposed) | View |
Page 428 of 20943, showing 5 records out of 104715 total, starting on record 2136, ending on 2140