2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3827 | MEDIUM | 5.4 | 0.6% | Feb 11, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenti... |
| CVE-2014-3826 | MEDIUM | 5.4 | 0.6% | Feb 11, 2020 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web... |
| CVE-2014-9470 | MEDIUM | 6.1 | 1.4% | Feb 8, 2020 | Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork C... |
| CVE-2014-9127 | MEDIUM | 6.5 | 1.4% | Feb 8, 2020 | Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote aut... |
| CVE-2014-9126 | MEDIUM | 6.1 | 1.1% | Feb 8, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to injec... |
| CVE-2014-5278 | MEDIUM | 5.3 | 1.5% | Feb 7, 2020 | A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs. |
| CVE-2014-6413 | MEDIUM | 6.1 | 1.2% | Feb 7, 2020 | A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/p... |
| CVE-2014-2875 | MEDIUM | 6.1 | 1.6% | Feb 6, 2020 | The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which al... |
| CVE-2014-10400 | MEDIUM | 6.1 | 1.2% | Feb 6, 2020 | The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predi... |
| CVE-2014-10399 | MEDIUM | 6.1 | 1.3% | Feb 6, 2020 | The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbit... |
| CVE-2014-8271 | MEDIUM | 6.8 | 0.4% | Feb 6, 2020 | Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain... |
| CVE-2014-8328 | MEDIUM | 5.3 | 1.6% | Feb 3, 2020 | The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attacker... |
| CVE-2014-8338 | MEDIUM | 6.1 | 1.3% | Jan 31, 2020 | Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhis... |
| CVE-2014-3809 | MEDIUM | 6.1 | 0.9% | Jan 31, 2020 | Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS... |
| CVE-2014-2843 | MEDIUM | 6.1 | 1.0% | Jan 31, 2020 | Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows ... |
| CVE-2014-4860 | MEDIUM | 6.8 | 0.5% | Jan 31, 2020 | Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI impl... |
| CVE-2014-4859 | MEDIUM | 6.8 | 0.6% | Jan 31, 2020 | Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation... |
| CVE-2014-3718 | MEDIUM | 6.1 | 1.0% | Jan 30, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library mana... |
| CVE-2014-8490 | MEDIUM | 6.1 | 0.8% | Jan 28, 2020 | Cross-site scripting (XSS) vulnerability in TennisConnect COMPONENTS 9.927 allows remote attackers to inject arbitrary w... |
| CVE-2014-3230 | MEDIUM | 5.9 | 1.6% | Jan 28, 2020 | The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket cla... |
| CVE-2014-5500 | MEDIUM | 6.1 | 0.8% | Jan 27, 2020 | Synacor Zimbra Collaboration before 8.0.8 has XSS. |
| CVE-2014-7301 | MEDIUM | 6.6 | 0.5% | Jan 27, 2020 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain pas... |
| CVE-2014-9481 | MEDIUM | 5.9 | 1.3% | Jan 27, 2020 | The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive ... |
| CVE-2014-8161 | MEDIUM | 4.3 | 2.5% | Jan 27, 2020 | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows re... |
| CVE-2014-4156 | MEDIUM | 5.3 | 1.2% | Jan 27, 2020 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now