2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8131 | — | — | 1.5% | Jan 6, 2015 | The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a do... |
| CVE-2014-7209 | — | — | 2.7% | Jan 6, 2015 | run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitr... |
| CVE-2014-3764 | — | — | 1.4% | Jan 6, 2015 | Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS befor... |
| CVE-2014-3628 | — | — | 4.7% | Jan 6, 2015 | Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows rem... |
| CVE-2014-9526 | — | — | 1.9% | Jan 5, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to i... |
| CVE-2014-9525 | — | — | 1.2% | Jan 5, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Timed Popup (wp-timed-popup) plugin 1.3 for WordPress ... |
| CVE-2014-9524 | — | — | 1.2% | Jan 5, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin b... |
| CVE-2014-9523 | — | — | 1.0% | Jan 5, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.... |
| CVE-2014-9522 | — | — | 3.5% | Jan 5, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject... |
| CVE-2014-9521 | — | — | 2.3% | Jan 5, 2015 | Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles q... |
| CVE-2014-9520 | — | — | 1.2% | Jan 5, 2015 | SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arb... |
| CVE-2014-9519 | — | — | 1.2% | Jan 5, 2015 | SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbit... |
| CVE-2014-9518 | — | — | 1.0% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router DIR-655 (rev Bx) with firmware before 2.12b01 all... |
| CVE-2014-9517 | — | — | 2.4% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers ... |
| CVE-2014-9516 | — | — | 1.5% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web... |
| CVE-2014-9389 | — | — | 1.9% | Jan 5, 2015 | Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or writ... |
| CVE-2014-8085 | — | — | 2.5% | Jan 5, 2015 | Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php ... |
| CVE-2014-8084 | — | — | 3.2% | Jan 5, 2015 | Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attac... |
| CVE-2014-8083 | — | — | 2.4% | Jan 5, 2015 | SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execut... |
| CVE-2014-2598 | — | — | 3.5% | Jan 5, 2015 | Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows... |
| CVE-2014-1679 | — | — | 1.2% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite before 7.2.2-rev31, 7.4.0 before 7.4.0-rev27, and... |
| CVE-2014-9492 | — | — | — | Jan 5, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9323. Reason: This candidate is a reservation ... |
| CVE-2014-9509 | — | — | 1.5% | Jan 4, 2015 | The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, w... |
| CVE-2014-9508 | — | — | 1.7% | Jan 4, 2015 | The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, w... |
| CVE-2014-9507 | — | — | 1.0% | Jan 4, 2015 | MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgContentHandlerUseDB is enabled, allows remote... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now