2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2014-3827MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenti...
CVE-2014-3826MEDIUM5.4Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web...
CVE-2014-9470MEDIUM6.1Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork C...
CVE-2014-9127MEDIUM6.5Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote aut...
CVE-2014-9126MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to injec...
CVE-2014-5278MEDIUM5.3A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.
CVE-2014-6413MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/p...
CVE-2014-2875MEDIUM6.1The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which al...
CVE-2014-10400MEDIUM6.1The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predi...
CVE-2014-10399MEDIUM6.1The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbit...
CVE-2014-8271MEDIUM6.8Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain...
CVE-2014-8328MEDIUM5.3The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attacker...
CVE-2014-8338MEDIUM6.1Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhis...
CVE-2014-3809MEDIUM6.1Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS...
CVE-2014-2843MEDIUM6.1Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows ...
CVE-2014-4860MEDIUM6.8Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI impl...
CVE-2014-4859MEDIUM6.8Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation...
CVE-2014-3718MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library mana...
CVE-2014-8490MEDIUM6.1Cross-site scripting (XSS) vulnerability in TennisConnect COMPONENTS 9.927 allows remote attackers to inject arbitrary w...
CVE-2014-3230MEDIUM5.9The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket cla...
CVE-2014-5500MEDIUM6.1Synacor Zimbra Collaboration before 8.0.8 has XSS.
CVE-2014-7301MEDIUM6.6SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain pas...
CVE-2014-9481MEDIUM5.9The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive ...
CVE-2014-8161MEDIUM4.3PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows re...
CVE-2014-4156MEDIUM5.3Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now