2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9740Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authen...
CVE-2014-9739Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authe...
CVE-2014-9738Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow rem...
CVE-2014-9737Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote att...
CVE-2014-3653Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attacker...
CVE-2014-1836Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows ...
CVE-2014-1750Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote ...
CVE-2014-9735The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier...
CVE-2014-9734Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att...
CVE-2014-4768IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices al...
CVE-2014-9230Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Preve...
CVE-2014-6198Cross-site request forgery (CSRF) vulnerability in IBM Security Network Protection 5.3 before 5.3.1 allows remote attack...
CVE-2014-4875CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, ...
CVE-2014-4882Aptexx Resident Anywhere does not require authentication, which allows remote attackers to obtain sensitive information ...
CVE-2014-8176The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h ...
CVE-2014-9732The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certai...
CVE-2014-8607The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command lin...
CVE-2014-8606Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administ...
CVE-2014-8605The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under t...
CVE-2014-8604The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th...
CVE-2014-8603cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to exe...
CVE-2014-7872Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges...
CVE-2014-9284The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and ea...
CVE-2014-6284SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the c...
CVE-2014-7810The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now