2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8773——MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mec...
CVE-2014-8772——Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticate...
CVE-2014-8771——Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote at...
CVE-2014-8104——OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause ...
CVE-2014-9220——SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbi...
CVE-2014-9141——The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which all...
CVE-2014-3988——Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to i...
CVE-2014-9184——ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd....
CVE-2014-9183——ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administra...
CVE-2014-9182——models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail message...
CVE-2014-9181——Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrar...
CVE-2014-9180——Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites an...
CVE-2014-9179——Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe...
CVE-2014-9178——Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu...
CVE-2014-9177——The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installati...
CVE-2014-9176——Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attac...
CVE-2014-9175——SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote...
CVE-2014-9174——Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before...
CVE-2014-9173——SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta...
CVE-2014-9116——The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, w...
CVE-2014-9113——CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use...
CVE-2014-9112——Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of...
CVE-2014-8874——The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, wh...
CVE-2014-8789——GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrar...
CVE-2014-8788——GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now