2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-5110Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inje...
CVE-2014-5109SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker...
CVE-2014-5108Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attac...
CVE-2014-5107concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics...
CVE-2014-5106Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows ...
CVE-2014-5105Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce 2.1.1 allow remote attackers to inject arbitrary web ...
CVE-2014-5104Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via...
CVE-2014-4726Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspeci...
CVE-2014-4725The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen...
CVE-2014-4971Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write ...
CVE-2014-4857Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web...
CVE-2014-4748Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote...
CVE-2014-4747The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeti...
CVE-2014-2966The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote...
CVE-2014-2626Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Vi...
CVE-2014-2625Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Vir...
CVE-2014-4979Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...
CVE-2014-4858Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier all...
CVE-2014-3328The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of servic...
CVE-2014-3326SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users...
CVE-2014-3324Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TeleP...
CVE-2014-3305Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earl...
CVE-2014-3301The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to ob...
CVE-2014-3071Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows re...
CVE-2014-2363Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain ac...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now