2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4938 | — | — | 3.0% | Jul 11, 2014 | SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e... |
| CVE-2014-4937 | — | — | 8.9% | Jul 11, 2014 | Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to... |
| CVE-2014-4738 | — | — | 1.2% | Jul 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x before 5.2.1 allow re... |
| CVE-2014-3822 | — | — | 1.7% | Jul 11, 2014 | Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 be... |
| CVE-2014-3821 | — | — | 1.2% | Jul 11, 2014 | Cross-site scripting (XSS) vulnerability in SRX Web Authentication (webauth) in Juniper Junos 11.4 before 11.4R11, 12.1X... |
| CVE-2014-3819 | — | — | 2.7% | Jul 11, 2014 | Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R10, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 ... |
| CVE-2014-3817 | — | — | 3.4% | Jul 11, 2014 | Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, a... |
| CVE-2014-3816 | — | — | 2.2% | Jul 11, 2014 | Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 ... |
| CVE-2014-3815 | — | — | 1.8% | Jul 11, 2014 | Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to... |
| CVE-2014-4700 | — | — | 0.6% | Jul 11, 2014 | Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabl... |
| CVE-2014-4167 | — | — | 1.7% | Jul 11, 2014 | The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenti... |
| CVE-2014-3992 | — | — | 2.0% | Jul 11, 2014 | Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary S... |
| CVE-2014-3991 | — | — | 2.7% | Jul 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary... |
| CVE-2014-3503 | — | — | 6.0% | Jul 11, 2014 | Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attack... |
| CVE-2014-3499 | — | — | 0.4% | Jul 11, 2014 | Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to ga... |
| CVE-2014-3485 | — | — | 1.5% | Jul 11, 2014 | The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authe... |
| CVE-2014-0174 | — | — | 1.6% | Jul 11, 2014 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-C... |
| CVE-2014-4908 | — | — | 1.9% | Jul 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitr... |
| CVE-2014-4907 | — | — | 2.2% | Jul 11, 2014 | Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.2... |
| CVE-2014-4856 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remo... |
| CVE-2014-4855 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to in... |
| CVE-2014-4854 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the WP Construction Mode plugin 1.8 for WordPress allows remote attackers to... |
| CVE-2014-4853 | — | — | 1.9% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users ... |
| CVE-2014-4852 | — | — | 2.2% | Jul 10, 2014 | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to ... |
| CVE-2014-4851 | — | — | 1.1% | Jul 10, 2014 | Open redirect vulnerability in msg.php in FoeCMS allows remote attackers to redirect users to arbitrary web sites and co... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now