2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8800 | — | — | 3.8% | Dec 5, 2014 | Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before ... |
| CVE-2014-3997 | — | — | 9.2% | Dec 5, 2014 | SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manag... |
| CVE-2014-3996 | — | — | 35.5% | Dec 5, 2014 | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central... |
| CVE-2014-7868 | — | — | 73.3% | Dec 4, 2014 | Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT ... |
| CVE-2014-7867 | — | — | 39.9% | Dec 4, 2014 | SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEng... |
| CVE-2014-6036 | — | — | 39.1% | Dec 4, 2014 | Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Socia... |
| CVE-2014-6035 | — | — | 26.2% | Dec 4, 2014 | Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier al... |
| CVE-2014-6034 | — | — | 79.5% | Dec 4, 2014 | Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in Z... |
| CVE-2014-5446 | — | — | 54.7% | Dec 4, 2014 | Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 ... |
| CVE-2014-5445 | — | — | 98.2% | Dec 4, 2014 | Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a... |
| CVE-2014-9243 | — | — | 2.5% | Dec 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web... |
| CVE-2014-9242 | — | — | 2.1% | Dec 3, 2014 | SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary... |
| CVE-2014-9241 | — | — | 3.4% | Dec 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attack... |
| CVE-2014-9240 | — | — | 3.5% | Dec 3, 2014 | SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to ex... |
| CVE-2014-9239 | — | — | 1.4% | Dec 3, 2014 | SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (ak... |
| CVE-2014-9238 | — | — | 2.4% | Dec 3, 2014 | D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file param... |
| CVE-2014-9237 | — | — | 2.1% | Dec 3, 2014 | SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a... |
| CVE-2014-9236 | — | — | 2.6% | Dec 3, 2014 | Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier al... |
| CVE-2014-9235 | — | — | 2.1% | Dec 3, 2014 | Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated ... |
| CVE-2014-9234 | — | — | 2.8% | Dec 3, 2014 | Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remo... |
| CVE-2014-9157 | — | — | 5.6% | Dec 3, 2014 | Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have uns... |
| CVE-2014-9134 | — | — | 2.5% | Dec 3, 2014 | Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote ... |
| CVE-2014-9018 | — | — | 3.0% | Dec 3, 2014 | Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensiti... |
| CVE-2014-8775 | — | — | 2.8% | Dec 3, 2014 | MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, whic... |
| CVE-2014-8774 | — | — | 1.5% | Dec 3, 2014 | Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attacke... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now