2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8773 | — | — | 1.1% | Dec 3, 2014 | MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mec... |
| CVE-2014-8772 | — | — | 0.8% | Dec 3, 2014 | Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticate... |
| CVE-2014-8771 | — | — | 0.6% | Dec 3, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote at... |
| CVE-2014-8104 | — | — | 3.5% | Dec 3, 2014 | OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause ... |
| CVE-2014-9220 | — | — | 2.1% | Dec 3, 2014 | SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbi... |
| CVE-2014-9141 | — | — | 1.2% | Dec 3, 2014 | The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which all... |
| CVE-2014-3988 | — | — | 1.4% | Dec 3, 2014 | Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to i... |
| CVE-2014-9184 | — | — | 2.2% | Dec 2, 2014 | ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.... |
| CVE-2014-9183 | — | — | 3.6% | Dec 2, 2014 | ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administra... |
| CVE-2014-9182 | — | — | 1.0% | Dec 2, 2014 | models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail message... |
| CVE-2014-9181 | — | — | 9.5% | Dec 2, 2014 | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrar... |
| CVE-2014-9180 | — | — | 4.4% | Dec 2, 2014 | Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites an... |
| CVE-2014-9179 | — | — | 3.7% | Dec 2, 2014 | Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe... |
| CVE-2014-9178 | — | — | 4.7% | Dec 2, 2014 | Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu... |
| CVE-2014-9177 | — | — | 2.6% | Dec 2, 2014 | The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installati... |
| CVE-2014-9176 | — | — | 2.0% | Dec 2, 2014 | Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attac... |
| CVE-2014-9175 | — | — | 4.7% | Dec 2, 2014 | SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote... |
| CVE-2014-9174 | — | — | 2.0% | Dec 2, 2014 | Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before... |
| CVE-2014-9173 | — | — | 5.2% | Dec 2, 2014 | SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta... |
| CVE-2014-9116 | — | — | 9.7% | Dec 2, 2014 | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, w... |
| CVE-2014-9113 | — | — | 1.6% | Dec 2, 2014 | CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use... |
| CVE-2014-9112 | — | — | 7.1% | Dec 2, 2014 | Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of... |
| CVE-2014-8874 | — | — | 1.5% | Dec 2, 2014 | The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, wh... |
| CVE-2014-8789 | — | — | 3.2% | Dec 2, 2014 | GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrar... |
| CVE-2014-8788 | — | — | 1.8% | Dec 2, 2014 | GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now