2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8754 | — | — | 2.3% | Dec 2, 2014 | Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to r... |
| CVE-2014-8728 | — | — | 1.2% | Dec 2, 2014 | SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System a... |
| CVE-2014-8791 | — | — | 14.8% | Dec 2, 2014 | project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated ... |
| CVE-2014-5284 | — | — | 2.5% | Dec 2, 2014 | host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, whi... |
| CVE-2014-3703 | — | — | 2.2% | Dec 2, 2014 | OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libv... |
| CVE-2014-3068 | — | — | 1.2% | Dec 2, 2014 | IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8... |
| CVE-2014-3065 | — | — | 0.6% | Dec 2, 2014 | Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 ... |
| CVE-2014-9156 | — | — | 1.6% | Dec 1, 2014 | The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows ... |
| CVE-2014-9155 | — | — | 1.5% | Dec 1, 2014 | Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 ... |
| CVE-2014-9154 | — | — | 0.9% | Dec 1, 2014 | The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes o... |
| CVE-2014-9153 | — | — | 0.9% | Dec 1, 2014 | Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authent... |
| CVE-2014-9152 | — | — | 2.3% | Dec 1, 2014 | The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when c... |
| CVE-2014-9151 | — | — | 1.4% | Dec 1, 2014 | The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, whic... |
| CVE-2014-5268 | — | — | 1.1% | Dec 1, 2014 | The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafte... |
| CVE-2014-9087 | — | — | 5.2% | Dec 1, 2014 | Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to ... |
| CVE-2014-9050 | — | — | 4.9% | Dec 1, 2014 | Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers ... |
| CVE-2014-8867 | — | — | 0.5% | Dec 1, 2014 | The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking ... |
| CVE-2014-8866 | — | — | 0.4% | Dec 1, 2014 | The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, a... |
| CVE-2014-8749 | — | — | 1.9% | Dec 1, 2014 | Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin befo... |
| CVE-2014-7816 | — | — | 25.1% | Dec 1, 2014 | Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.... |
| CVE-2014-7291 | — | — | 1.1% | Dec 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in api_events.php in Springshare LibCal 2.0 allow remote attackers t... |
| CVE-2014-5237 | — | — | 2.4% | Dec 1, 2014 | Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before... |
| CVE-2014-2233 | — | — | 2.0% | Dec 1, 2014 | Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.4... |
| CVE-2014-2232 | — | — | 1.3% | Dec 1, 2014 | Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows re... |
| CVE-2014-8961 | — | — | 2.5% | Nov 30, 2014 | Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x b... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now