2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4719 | — | — | 1.4% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 al... |
| CVE-2014-4718 | — | — | 2.3% | Jul 3, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack th... |
| CVE-2014-4717 | — | — | 2.8% | Jul 3, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordP... |
| CVE-2014-4716 | — | — | 2.3% | Jul 3, 2014 | Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authenticatio... |
| CVE-2014-4195 | — | — | 1.4% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to inject arbit... |
| CVE-2014-4002 | — | — | 2.1% | Jul 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web scrip... |
| CVE-2014-3920 | — | — | 0.7% | Jul 3, 2014 | Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentic... |
| CVE-2014-3857 | — | — | 2.2% | Jul 3, 2014 | Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before ... |
| CVE-2014-3538 | — | — | 11.8% | Jul 3, 2014 | file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers... |
| CVE-2014-3149 | — | — | 1.9% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4... |
| CVE-2014-2965 | — | — | 2.5% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in auth-settings-x.php in SpamTitan before 6.04 allows remote attackers to inje... |
| CVE-2014-0325 | — | — | 16.1% | Jul 3, 2014 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause... |
| CVE-2014-4715 | — | — | 2.8% | Jul 3, 2014 | Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not prop... |
| CVE-2014-4667 | — | — | 5.9% | Jul 3, 2014 | The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a ... |
| CVE-2014-4656 | — | — | 0.5% | Jul 3, 2014 | Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 ... |
| CVE-2014-4655 | — | — | 0.5% | Jul 3, 2014 | The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15... |
| CVE-2014-4654 | — | — | 0.5% | Jul 3, 2014 | The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15... |
| CVE-2014-4653 | — | — | 0.5% | Jul 3, 2014 | sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of ... |
| CVE-2014-4652 | — | — | 0.3% | Jul 3, 2014 | Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALS... |
| CVE-2014-4611 | — | — | 8.1% | Jul 3, 2014 | Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress f... |
| CVE-2014-4614 | — | — | 0.7% | Jul 2, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the a... |
| CVE-2014-4606 | — | — | 1.6% | Jul 2, 2014 | Cross-site scripting (XSS) vulnerability in redirect_to_zeenshare.php in the ZeenShare plugin 1.0.1 and earlier for Word... |
| CVE-2014-4597 | — | — | 1.6% | Jul 2, 2014 | Cross-site scripting (XSS) vulnerability in test.php in the WP Social Invitations plugin before 1.4.4.3 for WordPress al... |
| CVE-2014-4591 | — | — | 1.6% | Jul 2, 2014 | Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPres... |
| CVE-2014-4581 | — | — | 1.6% | Jul 2, 2014 | Cross-site scripting (XSS) vulnerability in facture.php in the WPCB plugin 2.4.8 and earlier for WordPress allows remote... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now