2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9524 | — | — | 1.2% | Jan 5, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin b... |
| CVE-2014-9523 | — | — | 1.0% | Jan 5, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.... |
| CVE-2014-9522 | — | — | 3.5% | Jan 5, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject... |
| CVE-2014-9521 | — | — | 2.3% | Jan 5, 2015 | Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles q... |
| CVE-2014-9520 | — | — | 1.2% | Jan 5, 2015 | SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arb... |
| CVE-2014-9519 | — | — | 1.2% | Jan 5, 2015 | SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbit... |
| CVE-2014-9518 | — | — | 1.0% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router DIR-655 (rev Bx) with firmware before 2.12b01 all... |
| CVE-2014-9517 | — | — | 2.4% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers ... |
| CVE-2014-9516 | — | — | 1.5% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web... |
| CVE-2014-9389 | — | — | 1.9% | Jan 5, 2015 | Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or writ... |
| CVE-2014-8085 | — | — | 2.5% | Jan 5, 2015 | Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php ... |
| CVE-2014-8084 | — | — | 3.2% | Jan 5, 2015 | Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attac... |
| CVE-2014-8083 | — | — | 2.4% | Jan 5, 2015 | SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execut... |
| CVE-2014-2598 | — | — | 3.5% | Jan 5, 2015 | Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows... |
| CVE-2014-1679 | — | — | 1.2% | Jan 5, 2015 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite before 7.2.2-rev31, 7.4.0 before 7.4.0-rev27, and... |
| CVE-2014-9492 | — | — | — | Jan 5, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9323. Reason: This candidate is a reservation ... |
| CVE-2014-9509 | — | — | 1.5% | Jan 4, 2015 | The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, w... |
| CVE-2014-9508 | — | — | 1.7% | Jan 4, 2015 | The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, w... |
| CVE-2014-9507 | — | — | 1.0% | Jan 4, 2015 | MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgContentHandlerUseDB is enabled, allows remote... |
| CVE-2014-9506 | — | — | 1.0% | Jan 4, 2015 | MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue i... |
| CVE-2014-9277 | — | — | 2.0% | Jan 4, 2015 | The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14,... |
| CVE-2014-9276 | — | — | 0.7% | Jan 4, 2015 | Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.... |
| CVE-2014-9464 | — | — | 2.1% | Jan 3, 2015 | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute ar... |
| CVE-2014-9427 | — | — | 16.9% | Jan 3, 2015 | sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap... |
| CVE-2014-9461 | — | — | 2.1% | Jan 2, 2015 | Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remot... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now