2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-100008 | — | — | 2.0% | Jan 13, 2015 | Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel ... |
| CVE-2014-100007 | — | — | 2.0% | Jan 13, 2015 | Cross-site scripting (XSS) vulnerability in the HK Exif Tags plugin before 1.12 for WordPress allows remote authenticate... |
| CVE-2014-100006 | — | — | 1.1% | Jan 13, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in modules_v3/googlemap/wt_v3_street_view.php in webtrees before 1.5... |
| CVE-2014-100004 | — | — | 2.0% | Jan 13, 2015 | Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to in... |
| CVE-2014-100003 | — | — | 4.4% | Jan 13, 2015 | SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor... |
| CVE-2014-100002 | — | — | 59.9% | Jan 13, 2015 | Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb... |
| CVE-2014-100001 | — | — | 1.1% | Jan 13, 2015 | Cross-site request forgery (CSRF) vulnerability in the SEO Plugin LiveOptim plugin before 1.1.4-free for WordPress allow... |
| CVE-2014-100000 | — | — | — | Jan 13, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This ID is frequently used as an example o... |
| CVE-2014-10000 | — | — | — | Jan 13, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This ID is frequently used as an example o... |
| CVE-2014-6268 | — | — | 0.4% | Jan 12, 2015 | The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via... |
| CVE-2014-2839 | — | — | 1.6% | Jan 12, 2015 | SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arb... |
| CVE-2014-2838 | — | — | 1.0% | Jan 12, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote... |
| CVE-2014-9191 | — | — | 0.4% | Jan 10, 2015 | The CodeWrights HART Device Type Manager (DTM) library in Emerson HART DTM before 1.4.181 allows physically proximate at... |
| CVE-2014-9190 | — | — | 6.1% | Jan 10, 2015 | Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote ... |
| CVE-2014-8036 | — | — | 1.3% | Jan 10, 2015 | The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attacke... |
| CVE-2014-8035 | — | — | 1.4% | Jan 10, 2015 | The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whet... |
| CVE-2014-8020 | — | — | 2.4% | Jan 10, 2015 | Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU c... |
| CVE-2014-6212 | — | — | 1.4% | Jan 10, 2015 | The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x ... |
| CVE-2014-6199 | — | — | 2.0% | Jan 10, 2015 | The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote... |
| CVE-2014-6158 | — | — | 3.7% | Jan 10, 2015 | Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4... |
| CVE-2014-3096 | — | — | 0.8% | Jan 10, 2015 | Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authentica... |
| CVE-2014-1155 | — | — | — | Jan 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9580. Reason: This candidate is not authorized... |
| CVE-2014-1137 | — | — | — | Jan 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9445, CVE-2014-9581, CVE-2014-9582. Reason: Th... |
| CVE-2014-1004 | — | — | — | Jan 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9456. Reason: This candidate is not authorized... |
| CVE-2014-9585 | — | — | 0.6% | Jan 9, 2015 | The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locatio... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now