2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-10385——The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
CVE-2014-10384——The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
CVE-2014-10383——The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
CVE-2014-10379——The duplicate-post plugin before 2.6 for WordPress has SQL injection.
CVE-2014-10378——The duplicate-post plugin before 2.6 for WordPress has XSS.
CVE-2014-10377MEDIUM6.1The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
CVE-2014-10380——The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
CVE-2014-10381——The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
CVE-2014-10376——The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
CVE-2014-10375——handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
CVE-2014-8184HIGH7.8A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable...
CVE-2014-8183HIGH7.4It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on cert...
CVE-2014-10374——On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this...
CVE-2014-3798——The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (gu...
CVE-2014-9699——The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs,...
CVE-2014-9919——An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
CVE-2014-9918——An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
CVE-2014-9917——An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tri...
CVE-2014-1428LOW2A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affec...
CVE-2014-1427CRITICAL9.6A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cros...
CVE-2014-1426HIGH8.6A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any...
CVE-2014-9186——A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before ...
CVE-2014-5436——A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x be...
CVE-2014-5435——An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6...
CVE-2014-3603——The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 a...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now