2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9506 | — | — | 1.0% | Jan 4, 2015 | MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue i... |
| CVE-2014-9277 | — | — | 2.0% | Jan 4, 2015 | The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14,... |
| CVE-2014-9276 | — | — | 0.7% | Jan 4, 2015 | Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.... |
| CVE-2014-9464 | — | — | 2.1% | Jan 3, 2015 | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute ar... |
| CVE-2014-9427 | — | — | 16.9% | Jan 3, 2015 | sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap... |
| CVE-2014-9461 | — | — | 2.1% | Jan 2, 2015 | Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remot... |
| CVE-2014-9428 | — | — | 5.4% | Jan 2, 2015 | The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux... |
| CVE-2014-9460 | — | — | 1.2% | Jan 2, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow re... |
| CVE-2014-9459 | — | — | 1.1% | Jan 2, 2015 | Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2... |
| CVE-2014-9458 | — | — | 1.9% | Jan 2, 2015 | Heap-based buffer overflow in the GDB debugger module in Hex-Rays IDA Pro before 6.6 cumulative fix 2014-12-24 allows re... |
| CVE-2014-9457 | — | — | 1.1% | Jan 2, 2015 | SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users... |
| CVE-2014-9456 | — | — | 10.5% | Jan 2, 2015 | Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev... |
| CVE-2014-9455 | — | — | 1.3% | Jan 2, 2015 | SQL injection vulnerability in showads.php in CTS Projects & Software ClassAd 3.0 allows remote attackers to execute arb... |
| CVE-2014-9454 | — | — | 1.2% | Jan 2, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Sticky Footer plugin before 1.3.3 for WordPress... |
| CVE-2014-9453 | — | — | 1.6% | Jan 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in simple-visitor-stat.php in the Simple visitor stat plugin for Wor... |
| CVE-2014-9452 | — | — | 2.8% | Jan 2, 2015 | Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary... |
| CVE-2014-9451 | — | — | 4.6% | Jan 2, 2015 | Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.... |
| CVE-2014-9450 | — | — | 1.3% | Jan 2, 2015 | Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, an... |
| CVE-2014-9449 | — | — | 3.7% | Jan 2, 2015 | Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cau... |
| CVE-2014-9448 | — | — | 6.3% | Jan 2, 2015 | Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or ... |
| CVE-2014-9447 | — | — | 5.0% | Jan 2, 2015 | Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allo... |
| CVE-2014-9446 | — | — | 1.2% | Jan 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 a... |
| CVE-2014-9445 | — | — | 1.3% | Jan 2, 2015 | SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to exec... |
| CVE-2014-9444 | — | — | 6.7% | Jan 2, 2015 | Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to ... |
| CVE-2014-7294 | — | — | 2.0% | Jan 2, 2015 | Open redirect vulnerability in the logon page in NYU OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now