2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7836 | — | — | 1.0% | Nov 24, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.... |
| CVE-2014-7835 | — | — | 1.4% | Nov 24, 2014 | webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a pr... |
| CVE-2014-7834 | — | — | 1.7% | Nov 24, 2014 | mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which a... |
| CVE-2014-7833 | — | — | 1.7% | Nov 24, 2014 | mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certai... |
| CVE-2014-7832 | — | — | 1.7% | Nov 24, 2014 | mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before ... |
| CVE-2014-7831 | — | — | 1.7% | Nov 24, 2014 | lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability be... |
| CVE-2014-7830 | — | — | 1.5% | Nov 24, 2014 | Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, ... |
| CVE-2014-5326 | — | — | 1.1% | Nov 24, 2014 | Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remo... |
| CVE-2014-5325 | — | — | 2.3% | Nov 24, 2014 | The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR)... |
| CVE-2014-5314 | — | — | 3.7% | Nov 24, 2014 | Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows ... |
| CVE-2014-6477 | — | — | 1.2% | Nov 23, 2014 | Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, ... |
| CVE-2014-8714 | — | — | 3.5% | Nov 23, 2014 | The dissect_write_structured_field function in epan/dissectors/packet-tn5250.c in the TN5250 dissector in Wireshark 1.10... |
| CVE-2014-8713 | — | — | 3.8% | Nov 23, 2014 | Stack-based buffer overflow in the build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector... |
| CVE-2014-8712 | — | — | 3.1% | Nov 23, 2014 | The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.1... |
| CVE-2014-8711 | — | — | 3.2% | Nov 23, 2014 | Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and... |
| CVE-2014-8710 | — | — | 3.1% | Nov 23, 2014 | The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before ... |
| CVE-2014-8626 | — | — | 5.8% | Nov 23, 2014 | Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allow... |
| CVE-2014-6183 | — | — | 1.8% | Nov 23, 2014 | IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 bef... |
| CVE-2014-4807 | — | — | 1.2% | Nov 23, 2014 | Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated use... |
| CVE-2014-8683 | — | — | 1.9% | Nov 21, 2014 | Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.... |
| CVE-2014-8682 | — | — | 34.3% | Nov 21, 2014 | Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r... |
| CVE-2014-8681 | — | — | 4.6% | Nov 21, 2014 | SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.... |
| CVE-2014-8539 | — | — | 1.9% | Nov 21, 2014 | Cross-site scripting (XSS) vulnerability in Simple Email Form 1.8.5 and earlier allows remote attackers to inject arbitr... |
| CVE-2014-8469 | — | — | 3.2% | Nov 21, 2014 | Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker... |
| CVE-2014-8090 | — | — | 5.6% | Nov 21, 2014 | The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 al... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now