2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3863 | — | — | 1.9% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to ... |
| CVE-2014-8364 | — | — | 1.6% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress... |
| CVE-2014-8363 | — | — | 2.1% | Oct 20, 2014 | SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remot... |
| CVE-2014-5169 | — | — | 1.4% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users ... |
| CVE-2014-5026 | — | — | 1.9% | Oct 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access... |
| CVE-2014-5025 | — | — | 1.8% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with cons... |
| CVE-2014-3564 | — | — | 4.3% | Oct 20, 2014 | Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in G... |
| CVE-2014-8331 | — | — | 0.5% | Oct 20, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C... |
| CVE-2014-8330 | — | — | 0.8% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or ... |
| CVE-2014-5276 | — | — | 2.6% | Oct 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated u... |
| CVE-2014-5275 | — | — | 1.9% | Oct 20, 2014 | Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote au... |
| CVE-2014-3978 | — | — | 1.7% | Oct 20, 2014 | SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands ... |
| CVE-2014-3830 | — | — | 1.4% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in info.php in TomatoCart 1.1.8.6.1 allows remote attackers to inject arbitrary... |
| CVE-2014-8329 | — | — | 2.1% | Oct 20, 2014 | Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insuf... |
| CVE-2014-5449 | — | — | 0.4% | Oct 20, 2014 | Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local... |
| CVE-2014-5448 | — | — | 0.4% | Oct 20, 2014 | Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensi... |
| CVE-2014-5447 | — | — | 0.4% | Oct 20, 2014 | Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obta... |
| CVE-2014-5098 | — | — | 1.9% | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in the Search module before 1.2.2 in Jamroom allows remote attackers to inject ... |
| CVE-2014-5094 | — | — | 5.5% | Oct 20, 2014 | Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.p... |
| CVE-2014-2081 | — | — | 2.1% | Oct 20, 2014 | Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua bef... |
| CVE-2014-6308 | — | — | 22.3% | Oct 20, 2014 | Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot ... |
| CVE-2014-6280 | — | — | 1.9% | Oct 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary w... |
| CVE-2014-7626 | — | — | 0.3% | Oct 20, 2014 | The Atme (aka com.bedigital.atme) application 1.0.10 for Android does not verify X.509 certificates from SSL servers, wh... |
| CVE-2014-7624 | — | — | 0.3% | Oct 20, 2014 | The Guess the Pixel Character Quiz (aka com.aiadp.pixelcQuiz) application 1.3 for Android does not verify X.509 certific... |
| CVE-2014-7622 | — | — | 0.3% | Oct 20, 2014 | The Affinity Mobile ATM Locator (aka com.collegemobile.affinity.locator) application 1.5 for Android does not verify X.5... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now