Skip to main content

Year archive

CVEs published in 2014

Archive summary

7,928 CVEs published in 2014 — 793 Critical, 1,160 High, 5,317 Medium, 658 Low, 0 Unrated.

CVE-2013-7243

Published Jan 17, 2014

Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1.2 and 3.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) post-menu field to e…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6632

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Vessio NetBill 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) file title to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6631

Published Jan 16, 2014

Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authentication of administrators for reques…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6630

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Media Library Categories plugin 1.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6629

Published Jan 16, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attackers to hijack the authentication of…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6628

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6627

Published Jan 16, 2014

Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6625

Published Jan 16, 2014

SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6624

Published Jan 16, 2014

Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6623

Published Jan 16, 2014

Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6622

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6621

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Email…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6620

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6725

Published Jan 16, 2014

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6330

Published Jan 16, 2014

IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6325

Published Jan 16, 2014

IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0667

Published Jan 16, 2014

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0666

Published Jan 16, 2014

Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of fil…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0650

Published Jan 16, 2014

The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this i…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0649

Published Jan 16, 2014

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtai…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0648

Published Jan 16, 2014

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6687

Published Jan 16, 2014

The web portal in the Enterprise License Manager component in Cisco WebEx Meetings Server allows remote authenticated users to discover the cleartext administrative password by re…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 7,601-7,625 of 7,928 CVEsPage 305 of 318