2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3599MEDIUM6.5HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
CVE-2014-9014MEDIUM4.3Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b...
CVE-2014-9013HIGH8.8The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth...
CVE-2014-3180CRITICAL9.1In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible ...
CVE-2014-8181MEDIUM5.5The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensi...
CVE-2014-3649MEDIUM6.1JBoss AeroGear has reflected XSS via the password field
CVE-2014-2304HIGH7.5A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attac...
CVE-2014-10397HIGH7.5The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts...
CVE-2014-10396HIGH7.5The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl...
CVE-2014-10049Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-9992Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-9982Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-10061Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-10060Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-10395The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2014-10393The cforms2 plugin before 10.5 for WordPress has XSS.
CVE-2014-10386The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
CVE-2014-10382The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
CVE-2014-10394The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
CVE-2014-10392The cforms2 plugin before 10.2 for WordPress has XSS.
CVE-2014-10391The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVE-2014-10390The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
CVE-2014-10389The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
CVE-2014-10388The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
CVE-2014-10387The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now