2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8621 | — | — | 3.0% | Oct 16, 2017 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut... |
| CVE-2014-8087 | — | — | 1.9% | Oct 16, 2017 | Cross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attacker... |
| CVE-2014-7851 | — | — | 1.0% | Oct 16, 2017 | oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote au... |
| CVE-2014-3702 | — | — | 1.9% | Oct 16, 2017 | Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files ... |
| CVE-2014-0029 | — | — | 0.8% | Oct 16, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote a... |
| CVE-2014-9092 | — | — | 3.2% | Oct 10, 2017 | libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related... |
| CVE-2014-9474 | — | — | 4.3% | Oct 10, 2017 | Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have uns... |
| CVE-2014-0030 | — | — | 16.9% | Oct 10, 2017 | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks... |
| CVE-2014-8957 | — | — | 1.2% | Oct 6, 2017 | Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary w... |
| CVE-2014-2903 | — | — | 1.0% | Oct 6, 2017 | CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a... |
| CVE-2014-0047 | — | — | 0.4% | Oct 6, 2017 | Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage. |
| CVE-2014-8758 | — | — | 1.2% | Oct 6, 2017 | Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attacker... |
| CVE-2014-8492 | — | — | 1.2% | Oct 6, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin befor... |
| CVE-2014-7240 | — | — | 1.2% | Oct 6, 2017 | Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote... |
| CVE-2014-0043 | — | — | 3.0% | Oct 3, 2017 | In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for th... |
| CVE-2014-2029 | — | — | 2.0% | Sep 29, 2017 | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obta... |
| CVE-2014-9686 | — | — | 1.6% | Sep 28, 2017 | The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a vi... |
| CVE-2014-8878 | — | — | 1.2% | Sep 28, 2017 | KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers t... |
| CVE-2014-8889 | — | — | 5.8% | Sep 26, 2017 | Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or... |
| CVE-2014-8170 | — | — | 3.5% | Sep 26, 2017 | ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packag... |
| CVE-2014-8156 | — | — | 0.5% | Sep 26, 2017 | The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-... |
| CVE-2014-0997 | — | — | 6.4% | Sep 26, 2017 | WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i... |
| CVE-2014-8686 | — | — | 37.2% | Sep 19, 2017 | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-... |
| CVE-2014-8684 | — | — | 71.5% | Sep 19, 2017 | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof... |
| CVE-2014-9619 | — | — | 7.4% | Sep 19, 2017 | Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now