2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8621SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut...
CVE-2014-8087Cross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attacker...
CVE-2014-7851oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote au...
CVE-2014-3702Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files ...
CVE-2014-0029Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote a...
CVE-2014-9092libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related...
CVE-2014-9474Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have uns...
CVE-2014-0030The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks...
CVE-2014-8957Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary w...
CVE-2014-2903CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a...
CVE-2014-0047Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.
CVE-2014-8758Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attacker...
CVE-2014-8492Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin befor...
CVE-2014-7240Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote...
CVE-2014-0043In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for th...
CVE-2014-2029The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obta...
CVE-2014-9686The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a vi...
CVE-2014-8878KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers t...
CVE-2014-8889Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or...
CVE-2014-8170ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packag...
CVE-2014-8156The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-...
CVE-2014-0997WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i...
CVE-2014-8686CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-...
CVE-2014-8684CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof...
CVE-2014-9619Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0....

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now