2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8772——Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticate...
CVE-2014-8771——Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote at...
CVE-2014-8104——OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause ...
CVE-2014-9220——SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbi...
CVE-2014-9141——The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which all...
CVE-2014-3988——Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to i...
CVE-2014-9184——ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd....
CVE-2014-9183——ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administra...
CVE-2014-9182——models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail message...
CVE-2014-9181——Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrar...
CVE-2014-9180——Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites an...
CVE-2014-9179——Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe...
CVE-2014-9178——Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu...
CVE-2014-9177——The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installati...
CVE-2014-9176——Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attac...
CVE-2014-9175——SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote...
CVE-2014-9174——Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before...
CVE-2014-9173——SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta...
CVE-2014-9116——The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, w...
CVE-2014-9113——CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use...
CVE-2014-9112——Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of...
CVE-2014-8874——The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, wh...
CVE-2014-8789——GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrar...
CVE-2014-8788——GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when...
CVE-2014-8754——Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to r...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now