2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8758 | — | — | 1.2% | Oct 6, 2017 | Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attacker... |
| CVE-2014-8492 | — | — | 1.2% | Oct 6, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin befor... |
| CVE-2014-7240 | — | — | 1.2% | Oct 6, 2017 | Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote... |
| CVE-2014-0043 | — | — | 3.0% | Oct 3, 2017 | In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for th... |
| CVE-2014-2029 | — | — | 2.0% | Sep 29, 2017 | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obta... |
| CVE-2014-9686 | — | — | 1.6% | Sep 28, 2017 | The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a vi... |
| CVE-2014-8878 | — | — | 1.2% | Sep 28, 2017 | KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers t... |
| CVE-2014-8889 | — | — | 5.8% | Sep 26, 2017 | Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or... |
| CVE-2014-8170 | — | — | 3.5% | Sep 26, 2017 | ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packag... |
| CVE-2014-8156 | — | — | 0.5% | Sep 26, 2017 | The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-... |
| CVE-2014-0997 | — | — | 6.4% | Sep 26, 2017 | WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i... |
| CVE-2014-9758 | MEDIUM | 6.1 | 1.0% | Sep 20, 2017 | Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1. |
| CVE-2014-8686 | — | — | 37.2% | Sep 19, 2017 | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-... |
| CVE-2014-8684 | — | — | 71.5% | Sep 19, 2017 | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof... |
| CVE-2014-9619 | — | — | 7.4% | Sep 19, 2017 | Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.... |
| CVE-2014-9618 | — | — | 73.3% | Sep 19, 2017 | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att... |
| CVE-2014-9616 | — | — | 2.4% | Sep 19, 2017 | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive informa... |
| CVE-2014-9611 | — | — | 12.7% | Sep 19, 2017 | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via ... |
| CVE-2014-9610 | — | — | 3.7% | Sep 19, 2017 | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an... |
| CVE-2014-8174 | — | — | 3.0% | Sep 19, 2017 | eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. |
| CVE-2014-6191 | — | — | 0.6% | Sep 19, 2017 | Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote ... |
| CVE-2014-5362 | — | — | 3.2% | Sep 19, 2017 | The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion... |
| CVE-2014-6106 | — | — | 0.9% | Sep 18, 2017 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attacke... |
| CVE-2014-9463 | — | — | 14.8% | Sep 15, 2017 | functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v... |
| CVE-2014-7808 | HIGH | 7.5 | 1.1% | Sep 15, 2017 | Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptog... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now