2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9498 | — | — | 0.9% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in the Webform Invitation module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-... |
| CVE-2014-9272 | — | — | 2.0% | Jan 9, 2015 | The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL proto... |
| CVE-2014-9271 | MEDIUM | 5.4 | 1.5% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated user... |
| CVE-2014-9269 | — | — | 2.0% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extende... |
| CVE-2014-8275 | — | — | 16.5% | Jan 9, 2015 | OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate... |
| CVE-2014-8033 | — | — | 1.4% | Jan 9, 2015 | The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via cra... |
| CVE-2014-8032 | — | — | 1.1% | Jan 9, 2015 | The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-pass... |
| CVE-2014-8031 | — | — | 0.6% | Jan 9, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the aut... |
| CVE-2014-8030 | — | — | 1.2% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in sendPwMail.do in Cisco WebEx Meetings Server allows remote attackers to inje... |
| CVE-2014-8029 | — | — | 1.2% | Jan 9, 2015 | Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to ... |
| CVE-2014-8028 | — | — | 1.2% | Jan 9, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) all... |
| CVE-2014-8027 | — | — | 1.6% | Jan 9, 2015 | The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Devic... |
| CVE-2014-3572 | — | — | 6.6% | Jan 9, 2015 | The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k ... |
| CVE-2014-3571 | — | — | 23.0% | Jan 9, 2015 | OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of servic... |
| CVE-2014-3570 | — | — | 21.3% | Jan 9, 2015 | The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calc... |
| CVE-2014-9583 | — | — | 80.7% | Jan 8, 2015 | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC... |
| CVE-2014-9582 | — | — | 1.5% | Jan 8, 2015 | Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to... |
| CVE-2014-9581 | — | — | 3.6% | Jan 8, 2015 | Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read... |
| CVE-2014-9580 | — | — | 3.2% | Jan 8, 2015 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary... |
| CVE-2014-9579 | — | — | 1.7% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtai... |
| CVE-2014-9578 | — | — | 2.2% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allo... |
| CVE-2014-9577 | — | — | 1.8% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated... |
| CVE-2014-9576 | — | — | 2.3% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !... |
| CVE-2014-9575 | — | — | 2.4% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read... |
| CVE-2014-9473 | — | — | 14.6% | Jan 8, 2015 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now