2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-10385The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
CVE-2014-10384The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
CVE-2014-10383The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
CVE-2014-10379The duplicate-post plugin before 2.6 for WordPress has SQL injection.
CVE-2014-10378The duplicate-post plugin before 2.6 for WordPress has XSS.
CVE-2014-10377MEDIUM6.1The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
CVE-2014-10380The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
CVE-2014-10381The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
CVE-2014-10376The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
CVE-2014-10375handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
CVE-2014-8184HIGH7.8A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable...
CVE-2014-8183HIGH7.4It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on cert...
CVE-2014-10374On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this...
CVE-2014-3798The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (gu...
CVE-2014-9699The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs,...
CVE-2014-9919An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
CVE-2014-9918An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
CVE-2014-9917An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tri...
CVE-2014-1428LOW2A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affec...
CVE-2014-1427CRITICAL9.6A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cros...
CVE-2014-1426HIGH8.6A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any...
CVE-2014-9186A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before ...
CVE-2014-5436A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x be...
CVE-2014-5435An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6...
CVE-2014-3603The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 a...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now