2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3774Multiple cross-site scripting (XSS) vulnerabilities in items.php in TeamPass before 2.1.20 allow remote attackers to inj...
CVE-2014-3773Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL command...
CVE-2014-3772TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a di...
CVE-2014-3771TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request...
CVE-2014-3517api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, whe...
CVE-2014-3459Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execu...
CVE-2014-3429IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote att...
CVE-2014-5187Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read ...
CVE-2014-5186SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenti...
CVE-2014-5185SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor...
CVE-2014-5184SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote a...
CVE-2014-5183SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1...
CVE-2014-5182Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contr...
CVE-2014-5181Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress...
CVE-2014-5180SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 fo...
CVE-2014-3559The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, ev...
CVE-2014-3434Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, ...
CVE-2014-0479reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vect...
CVE-2014-5179The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access pe...
CVE-2014-5178Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated...
CVE-2014-5090admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell me...
CVE-2014-5089SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute ...
CVE-2014-5088Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via ...
CVE-2014-5082Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus al...
CVE-2014-3560NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to exec...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now