Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2014-2863
Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecif…
Commonspot Content Server
after 7.0.1
HIGH 10.0
CVE-2014-2864EPSS 5%
Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified …
Commonspot Content Server
after 7.0.1
HIGH 10.0
CVE-2014-2866
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to per…
Commonspot Content Server
after 7.0.1
HIGH 10.0
CVE-2014-2867
Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by…
Commonspot Content Server
after 7.0.1
HIGH 10.0
CVE-2014-2874EPSS 5%
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified c…
Commonspot Content Server
after 7.0.1
HIGH 7.5
CVE-2014-2859
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.
Commonspot Content Server
after 7.0.1
HIGH 7.5
CVE-2014-2865
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demons…
Commonspot Content Server
after 7.0.1
HIGH 7.5
CVE-2014-2868
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GE…
Commonspot Content Server
after 7.0.1
MEDIUM 6.5
CVE-2014-2862
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated user…
Commonspot Content Server
after 7.0.1
MEDIUM 5.0
CVE-2014-2869
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as d…
Commonspot Content Server
after 7.0.1
MEDIUM 5.0
CVE-2014-2870
The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which ma…
Commonspot Content Server
after 7.0.1
MEDIUM 5.0
CVE-2014-2871
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attacke…
Commonspot Content Server
after 7.0.1
MEDIUM 5.0
CVE-2014-2872
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing v…
Commonspot Content Server
after 7.0.1
MEDIUM 5.0
CVE-2014-2873
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obta…
Commonspot Content Server
after 7.0.1
MEDIUM 5.0
CVE-2005-4575
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.…
Commonspot Content Server
after 4.5