2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4965 | — | — | 3.2% | Jul 15, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbit... |
| CVE-2014-4964 | — | — | 2.3% | Jul 15, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijac... |
| CVE-2014-4963 | — | — | 3.7% | Jul 15, 2014 | Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.cu... |
| CVE-2014-4962 | — | — | 4.7% | Jul 15, 2014 | Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number... |
| CVE-2014-4663 | — | — | 9.8% | Jul 15, 2014 | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary... |
| CVE-2014-4031 | — | — | 0.9% | Jul 15, 2014 | The Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2.x through 6.2.6.62196, and 6.3... |
| CVE-2014-3953 | — | — | 0.4% | Jul 15, 2014 | FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data str... |
| CVE-2014-3952 | — | — | 0.3% | Jul 15, 2014 | FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer betwe... |
| CVE-2014-3419 | — | — | 0.5% | Jul 15, 2014 | Infoblox NetMRI before 6.8.5 has a default password of admin for the "root" MySQL database account, which makes it easie... |
| CVE-2014-3418 | — | — | 7.2% | Jul 15, 2014 | config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via she... |
| CVE-2014-1474 | — | — | 2.4% | Jul 15, 2014 | Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remo... |
| CVE-2014-3319 | — | — | 2.8% | Jul 14, 2014 | Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 1... |
| CVE-2014-3317 | — | — | 2.6% | Jul 14, 2014 | Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unifie... |
| CVE-2014-2955 | — | — | 2.8% | Jul 14, 2014 | Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IP... |
| CVE-2014-2951 | — | — | 2.3% | Jul 14, 2014 | Datum Systems SnIP on PSM-500 and PSM-4500 devices has a hardcoded password of admin for the admin account, which makes ... |
| CVE-2014-2950 | — | — | 1.7% | Jul 14, 2014 | Datum Systems SnIP on PSM-500 and PSM-4500 devices does not require authentication for FTP sessions, which allows remote... |
| CVE-2014-2926 | — | — | 0.3% | Jul 14, 2014 | kapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to... |
| CVE-2014-4946 | — | — | 1.3% | Jul 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde ... |
| CVE-2014-4945 | — | — | 1.3% | Jul 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde ... |
| CVE-2014-4944 | — | — | 3.6% | Jul 14, 2014 | Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress al... |
| CVE-2014-4013 | — | — | 0.6% | Jul 14, 2014 | SQL injection vulnerability in the Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2... |
| CVE-2014-4942 | — | — | 4.4% | Jul 11, 2014 | The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information... |
| CVE-2014-4941 | — | — | 4.3% | Jul 11, 2014 | Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to re... |
| CVE-2014-4940 | — | — | 18.7% | Jul 11, 2014 | Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attacker... |
| CVE-2014-4939 | — | — | 2.3% | Jul 11, 2014 | SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticate... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now