2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2014-0161MEDIUM5.9ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the ...
CVE-2014-0104MEDIUM5.9In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potenti...
CVE-2014-6420MEDIUM6.1Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc...
CVE-2014-4550MEDIUM6.1Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier...
CVE-2014-4536MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusi...
CVE-2014-4535MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote a...
CVE-2014-4567MEDIUM6.1Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder pl...
CVE-2014-4558MEDIUM6.1Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earli...
CVE-2014-4548MEDIUM6.1Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress ...
CVE-2014-4544MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote att...
CVE-2014-4539MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to i...
CVE-2014-4592MEDIUM6.1Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier f...
CVE-2014-4519MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attacker...
CVE-2014-4559MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3....
CVE-2014-4525MEDIUM6.1Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1....
CVE-2014-4523MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote ...
CVE-2014-8178MEDIUM5.5Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image ...
CVE-2014-8561MEDIUM6.5imagemagick 6.8.9.6 has remote DOS via infinite loop
CVE-2014-4913MEDIUM6.1ZF2014-03 has a potential cross site scripting vector in multiple view helpers
CVE-2014-3652MEDIUM6.1JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
CVE-2014-3536MEDIUM5.5CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
CVE-2014-2387MEDIUM4.4Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
CVE-2014-0241MEDIUM5.5rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
CVE-2014-0091MEDIUM5.3Foreman has improper input validation which could lead to partial Denial of Service
CVE-2014-0026MEDIUM6.5katello-headpin is vulnerable to CSRF in REST API

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now