2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3599MEDIUM6.5HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
CVE-2014-9014MEDIUM4.3Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b...
CVE-2014-9013HIGH8.8The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth...
CVE-2014-3180CRITICAL9.1In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible ...
CVE-2014-8181MEDIUM5.5The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensi...
CVE-2014-3649MEDIUM6.1JBoss AeroGear has reflected XSS via the password field
CVE-2014-2304HIGH7.5A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attac...
CVE-2014-10397HIGH7.5The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts...
CVE-2014-10396HIGH7.5The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl...
CVE-2014-10049——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-9992——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-9982——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-10061——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-10060——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2014-10395——The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2014-10393——The cforms2 plugin before 10.5 for WordPress has XSS.
CVE-2014-10386——The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
CVE-2014-10382——The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
CVE-2014-10394——The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
CVE-2014-10392——The cforms2 plugin before 10.2 for WordPress has XSS.
CVE-2014-10391——The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVE-2014-10390——The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
CVE-2014-10389——The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
CVE-2014-10388——The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
CVE-2014-10387——The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now