2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9720 | MEDIUM | 6.5 | 2.5% | Jan 24, 2020 | Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, wh... |
| CVE-2014-2050 | MEDIUM | 6.5 | 1.5% | Jan 23, 2020 | Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote at... |
| CVE-2014-7238 | MEDIUM | 6.1 | 1.1% | Jan 23, 2020 | The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS |
| CVE-2014-9211 | MEDIUM | 6.1 | 0.9% | Jan 14, 2020 | ClickDesk version 4.3 and below has persistent cross site scripting |
| CVE-2014-9382 | MEDIUM | 6.5 | 0.8% | Jan 13, 2020 | Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation |
| CVE-2014-4561 | MEDIUM | 6.1 | 3.7% | Jan 10, 2020 | The ultimate-weather plugin 1.0 for WordPress has XSS |
| CVE-2014-4530 | MEDIUM | 6.1 | 0.9% | Jan 10, 2020 | flog plugin 0.1 for WordPress has XSS |
| CVE-2014-5012 | MEDIUM | 6.5 | 1.3% | Jan 10, 2020 | DOMPDF before 0.6.2 allows denial of service. |
| CVE-2014-5011 | MEDIUM | 6.5 | 1.6% | Jan 10, 2020 | DOMPDF before 0.6.2 allows Information Disclosure. |
| CVE-2014-3753 | MEDIUM | 5.5 | 0.9% | Jan 9, 2020 | AgileBits 1Password through 1.0.9.340 allows security feature bypass |
| CVE-2014-9908 | MEDIUM | 6.5 | 0.4% | Jan 8, 2020 | A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to bloc... |
| CVE-2014-1454 | MEDIUM | 4.8 | 0.6% | Jan 8, 2020 | Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user inp... |
| CVE-2014-5209 | MEDIUM | 5.3 | 2.5% | Jan 8, 2020 | An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control me... |
| CVE-2014-9405 | MEDIUM | 5.4 | 1.5% | Jan 6, 2020 | A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebo... |
| CVE-2014-8674 | MEDIUM | 5.4 | 2.6% | Jan 6, 2020 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the doc... |
| CVE-2014-3743 | MEDIUM | 6.1 | 1.7% | Jan 6, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers... |
| CVE-2014-5516 | MEDIUM | 6.5 | 1.3% | Jan 3, 2020 | Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0... |
| CVE-2014-4196 | MEDIUM | 6.1 | 0.8% | Jan 3, 2020 | Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attack... |
| CVE-2014-10398 | MEDIUM | 6.1 | 0.8% | Jan 3, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client ... |
| CVE-2014-6275 | MEDIUM | 5.9 | 0.9% | Jan 2, 2020 | FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by d... |
| CVE-2014-3590 | MEDIUM | 6.5 | 0.5% | Jan 2, 2020 | Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Th... |
| CVE-2014-0245 | MEDIUM | 5.9 | 1.0% | Jan 2, 2020 | It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For ... |
| CVE-2014-0183 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the syste... |
| CVE-2014-0169 | MEDIUM | 6.5 | 0.8% | Jan 2, 2020 | In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the se... |
| CVE-2014-4553 | MEDIUM | 6.1 | 1.2% | Jan 2, 2020 | Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attacker... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now