2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0011 | CRITICAL | 9.8 | 2.5% | Jan 2, 2020 | Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, wh... |
| CVE-2014-4553 | MEDIUM | 6.1 | 1.2% | Jan 2, 2020 | Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attacker... |
| CVE-2014-0161 | MEDIUM | 5.9 | 0.4% | Jan 2, 2020 | ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the ... |
| CVE-2014-0104 | MEDIUM | 5.9 | 0.8% | Jan 2, 2020 | In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potenti... |
| CVE-2014-0048 | CRITICAL | 9.8 | 6.5% | Jan 2, 2020 | An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed... |
| CVE-2014-6420 | MEDIUM | 6.1 | 1.8% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-5289 | CRITICAL | 9.8 | 12.0% | Dec 27, 2019 | Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request... |
| CVE-2014-3136 | HIGH | 8.8 | 2.9% | Dec 27, 2019 | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote a... |
| CVE-2014-4550 | MEDIUM | 6.1 | 3.9% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier... |
| CVE-2014-4536 | MEDIUM | 6.1 | 3.9% | Dec 27, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusi... |
| CVE-2014-4535 | MEDIUM | 6.1 | 4.0% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote a... |
| CVE-2014-4567 | MEDIUM | 6.1 | 1.2% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder pl... |
| CVE-2014-4558 | MEDIUM | 6.1 | 4.1% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earli... |
| CVE-2014-4548 | MEDIUM | 6.1 | 1.2% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress ... |
| CVE-2014-4544 | MEDIUM | 6.1 | 3.8% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote att... |
| CVE-2014-4539 | MEDIUM | 6.1 | 4.0% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to i... |
| CVE-2014-4592 | MEDIUM | 6.1 | 3.9% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier f... |
| CVE-2014-4519 | MEDIUM | 6.1 | 1.2% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attacker... |
| CVE-2014-4559 | MEDIUM | 6.1 | 1.2% | Dec 27, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.... |
| CVE-2014-4525 | MEDIUM | 6.1 | 1.2% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.... |
| CVE-2014-4523 | MEDIUM | 6.1 | 1.2% | Dec 27, 2019 | Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote ... |
| CVE-2014-8179 | HIGH | 7.5 | 2.7% | Dec 17, 2019 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest obj... |
| CVE-2014-8178 | MEDIUM | 5.5 | 0.5% | Dec 17, 2019 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image ... |
| CVE-2014-8650 | CRITICAL | 9.8 | 3.6% | Dec 15, 2019 | python-requests-Kerberos through 0.5 does not handle mutual authentication |
| CVE-2014-8561 | MEDIUM | 6.5 | 2.2% | Dec 15, 2019 | imagemagick 6.8.9.6 has remote DOS via infinite loop |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now