Skip to main content

Year archive

CVEs published in 2014

Archive summary

7,928 CVEs published in 2014 — 793 Critical, 1,160 High, 5,317 Medium, 658 Low, 0 Unrated.

CVE-2013-4200

Published Jan 21, 2014

The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relativ…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2594

Published Jan 21, 2014

SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1620

Published Jan 21, 2014

Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name1, (2) em…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1619

Published Jan 21, 2014

Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQL commands via the (1) resource_id or (2) version_id parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1618

Published Jan 21, 2014

Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1452

Published Jan 21, 2014

Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers to cause a denial of service (daemon crash) and possibly exe…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6872

Published Jan 21, 2014

SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a project…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6305

Published Jan 21, 2014

IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it ea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0753

Published Jan 21, 2014

Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5429

Published Jan 21, 2014

The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before F…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6635

Published Jan 21, 2014

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensiti…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6634

Published Jan 21, 2014

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6633

Published Jan 21, 2014

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editabl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5270

Published Jan 21, 2014

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5297

Published Jan 21, 2014

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authentica…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-5296

Published Jan 21, 2014

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5295

Published Jan 21, 2014

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's autho…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5294

Published Jan 21, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5293

Published Jan 21, 2014

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restr…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0010

Published Jan 20, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0009

Published Jan 20, 2014

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0008

Published Jan 20, 2014

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrator…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0668

Published Jan 20, 2014

Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 7,551-7,575 of 7,928 CVEsPage 303 of 318