Skip to main content

Year archive

CVEs published in 2014

Archive summary

7,928 CVEs published in 2014 — 793 Critical, 1,160 High, 5,317 Medium, 658 Low, 0 Unrated.

CVE-2014-9433

Published Dec 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inje…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-9432

Published Dec 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in templates/2k11/admin/overview.inc.tpl in Serendipity before 2.0-rc2 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9431

Published Dec 31, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to hijack the authentication of administrators for requests…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9430

Published Dec 31, 2014

Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9429

Published Dec 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to inject arbitrary web script or HTML via the (1) PROFILENAME par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9119

Published Dec 31, 2014

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8144

Published Dec 31, 2014

Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5284

Published Dec 31, 2014

Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5283

Published Dec 31, 2014

Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9399

Published Dec 31, 2014

Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9398

Published Dec 31, 2014

Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrato…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9397

Published Dec 31, 2014

Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin for WordPress allows remote attackers to hijack the authentication of administrators for requests that condu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9396

Published Dec 31, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleFlickr plugin 3.0.3 and earlier for WordPress allow remote attackers to hijack the authentication of admini…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9395

Published Dec 31, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the Simplelife plugin 1.2 and earlier for WordPress allow remote attackers to hijack the authentication of administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9394

Published Dec 31, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the PWGRandom plugin 1.11 and earlier for WordPress allow remote attackers to hijack the authentication of administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9393

Published Dec 31, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and earlier for WordPress allow remote attackers to hijack the authentication of admin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9392

Published Dec 31, 2014

Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attackers to hijack the authenticat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9391

Published Dec 31, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9367

Published Dec 31, 2014

Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers to conduct cross-site scripting (XSS) attacks via a "…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9325

Published Dec 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in TWiki 6.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERYSTRING variable in lib/TWiki.pm o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9254

Published Dec 31, 2014

bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8752

Published Dec 31, 2014

Multiple cross-site scripting (XSS) vulnerabilities in view.php in JCE-Tech PHP Video Script (aka Video Niche Script) 4.0 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 7,928 CVEsPage 1 of 318