2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-5195Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switchin...
CVE-2014-5194Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbi...
CVE-2014-5193Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary...
CVE-2014-5192SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL command...
CVE-2014-5191Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to injec...
CVE-2014-5190Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 ...
CVE-2014-5189SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers...
CVE-2014-5188Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers ...
CVE-2014-4647Stack-based buffer overflow in the loadExtensionFactory method in the TSVisualization ActiveX control in Embarcadero ER/...
CVE-2014-3914Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows ...
CVE-2014-3855Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a ....
CVE-2014-3854Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack ...
CVE-2014-3853Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attack...
CVE-2014-3852Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remo...
CVE-2014-3851usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local ...
CVE-2014-3800XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names ...
CVE-2014-3774Multiple cross-site scripting (XSS) vulnerabilities in items.php in TeamPass before 2.1.20 allow remote attackers to inj...
CVE-2014-3773Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL command...
CVE-2014-3772TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a di...
CVE-2014-3771TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request...
CVE-2014-3517api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, whe...
CVE-2014-3459Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execu...
CVE-2014-3429IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote att...
CVE-2014-5187Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read ...
CVE-2014-5186SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenti...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now