2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2014-9720MEDIUM6.5Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, wh...
CVE-2014-2050MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote at...
CVE-2014-7238MEDIUM6.1The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
CVE-2014-9211MEDIUM6.1ClickDesk version 4.3 and below has persistent cross site scripting
CVE-2014-9382MEDIUM6.5Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
CVE-2014-4561MEDIUM6.1The ultimate-weather plugin 1.0 for WordPress has XSS
CVE-2014-4530MEDIUM6.1flog plugin 0.1 for WordPress has XSS
CVE-2014-5012MEDIUM6.5DOMPDF before 0.6.2 allows denial of service.
CVE-2014-5011MEDIUM6.5DOMPDF before 0.6.2 allows Information Disclosure.
CVE-2014-3753MEDIUM5.5AgileBits 1Password through 1.0.9.340 allows security feature bypass
CVE-2014-9908MEDIUM6.5A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to bloc...
CVE-2014-1454MEDIUM4.8Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user inp...
CVE-2014-5209MEDIUM5.3An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control me...
CVE-2014-9405MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebo...
CVE-2014-8674MEDIUM5.4Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the doc...
CVE-2014-3743MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers...
CVE-2014-5516MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0...
CVE-2014-4196MEDIUM6.1Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attack...
CVE-2014-10398MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client ...
CVE-2014-6275MEDIUM5.9FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by d...
CVE-2014-3590MEDIUM6.5Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Th...
CVE-2014-0245MEDIUM5.9It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For ...
CVE-2014-0183MEDIUM6.1Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the syste...
CVE-2014-0169MEDIUM6.5In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the se...
CVE-2014-4553MEDIUM6.1Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attacker...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now