2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0011CRITICAL9.8Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, wh...
CVE-2014-4553MEDIUM6.1Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attacker...
CVE-2014-0161MEDIUM5.9ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the ...
CVE-2014-0104MEDIUM5.9In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potenti...
CVE-2014-0048CRITICAL9.8An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed...
CVE-2014-6420MEDIUM6.1Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc...
CVE-2014-5289CRITICAL9.8Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request...
CVE-2014-3136HIGH8.8Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote a...
CVE-2014-4550MEDIUM6.1Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier...
CVE-2014-4536MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusi...
CVE-2014-4535MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote a...
CVE-2014-4567MEDIUM6.1Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder pl...
CVE-2014-4558MEDIUM6.1Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earli...
CVE-2014-4548MEDIUM6.1Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress ...
CVE-2014-4544MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote att...
CVE-2014-4539MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to i...
CVE-2014-4592MEDIUM6.1Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier f...
CVE-2014-4519MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attacker...
CVE-2014-4559MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3....
CVE-2014-4525MEDIUM6.1Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1....
CVE-2014-4523MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote ...
CVE-2014-8179HIGH7.5Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest obj...
CVE-2014-8178MEDIUM5.5Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image ...
CVE-2014-8650CRITICAL9.8python-requests-Kerberos through 0.5 does not handle mutual authentication
CVE-2014-8561MEDIUM6.5imagemagick 6.8.9.6 has remote DOS via infinite loop

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now