2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3548 | — | — | 1.8% | Jul 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2... |
| CVE-2014-3547 | — | — | 1.2% | Jul 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in badges/renderer.php in Moodle 2.5.x before 2.5.7, 2.6.x before 2.... |
| CVE-2014-3546 | — | — | 1.4% | Jul 29, 2014 | Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enfo... |
| CVE-2014-3545 | — | — | 1.7% | Jul 29, 2014 | Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote... |
| CVE-2014-3544 | — | — | 4.7% | Jul 29, 2014 | Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before... |
| CVE-2014-3543 | — | — | 1.4% | Jul 29, 2014 | mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x ... |
| CVE-2014-3542 | — | — | 1.4% | Jul 29, 2014 | mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x bef... |
| CVE-2014-3541 | — | — | 3.7% | Jul 29, 2014 | The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.... |
| CVE-2014-3304 | — | — | 1.8% | Jul 28, 2014 | The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering cr... |
| CVE-2014-3303 | — | — | 2.0% | Jul 28, 2014 | The web framework in Cisco WebEx Meetings Server does not properly restrict the content of query strings, which allows r... |
| CVE-2014-2975 | — | — | 1.7% | Jul 28, 2014 | Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers ... |
| CVE-2014-2974 | — | — | 0.6% | Jul 28, 2014 | Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote at... |
| CVE-2014-5113 | — | — | 1.9% | Jul 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in test.php in Visualware MyConnection Server 9.7i allow remote atta... |
| CVE-2014-5112 | — | — | 9.2% | Jul 28, 2014 | maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacha... |
| CVE-2014-5111 | — | — | 21.2% | Jul 28, 2014 | Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..... |
| CVE-2014-5110 | — | — | 1.6% | Jul 28, 2014 | Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inje... |
| CVE-2014-5109 | — | — | 3.4% | Jul 28, 2014 | SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker... |
| CVE-2014-5108 | — | — | 2.3% | Jul 28, 2014 | Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attac... |
| CVE-2014-5107 | — | — | 3.0% | Jul 28, 2014 | concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics... |
| CVE-2014-5106 | — | — | 1.1% | Jul 28, 2014 | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows ... |
| CVE-2014-5105 | — | — | 1.4% | Jul 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce 2.1.1 allow remote attackers to inject arbitrary web ... |
| CVE-2014-5104 | — | — | 2.1% | Jul 28, 2014 | Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via... |
| CVE-2014-4726 | — | — | 1.7% | Jul 27, 2014 | Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspeci... |
| CVE-2014-4725 | — | — | 59.7% | Jul 27, 2014 | The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen... |
| CVE-2014-4971 | — | — | 23.0% | Jul 26, 2014 | Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now