2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4710Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbit...
CVE-2014-2226Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the...
CVE-2014-0475Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent a...
CVE-2014-0103WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users...
CVE-2014-3553mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, a...
CVE-2014-3552The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5...
CVE-2014-3551Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4...
CVE-2014-3550Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 a...
CVE-2014-3549Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in M...
CVE-2014-3548Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2...
CVE-2014-3547Multiple cross-site scripting (XSS) vulnerabilities in badges/renderer.php in Moodle 2.5.x before 2.5.7, 2.6.x before 2....
CVE-2014-3546Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enfo...
CVE-2014-3545Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote...
CVE-2014-3544Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before...
CVE-2014-3543mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x ...
CVE-2014-3542mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x bef...
CVE-2014-3541The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2....
CVE-2014-3120HIGH8.1The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut...
CVE-2014-3304The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering cr...
CVE-2014-3303The web framework in Cisco WebEx Meetings Server does not properly restrict the content of query strings, which allows r...
CVE-2014-2975Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers ...
CVE-2014-2974Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote at...
CVE-2014-5113Multiple cross-site scripting (XSS) vulnerabilities in test.php in Visualware MyConnection Server 9.7i allow remote atta...
CVE-2014-5112maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacha...
CVE-2014-5111Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .....

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now