2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-125120Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2014-125112CRITICAL9.8Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Sess...
CVE-2014-125128MEDIUM6.1'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't p...
CVE-2014-125127HIGH7.5The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager...
CVE-2014-125113CRITICAL9.3An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance vers...
CVE-2014-125126CRITICAL9.2An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated...
CVE-2014-125125HIGH8.8A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vul...
CVE-2014-125124CRITICAL10An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via ...
CVE-2014-125123CRITICAL10An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) pri...
CVE-2014-125122MEDIUM5.3A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router....
CVE-2014-125121CRITICAL10Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vul...
CVE-2014-125119HIGH8.4A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to ...
CVE-2014-125118CRITICAL9.4A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to pro...
CVE-2014-125117CRITICAL9.8A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W21...
CVE-2014-125116CRITICAL9.3A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the insta...
CVE-2014-125115CRITICAL10An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php e...
CVE-2014-125114HIGH8.4A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute ...
CVE-2014-7210CRITICAL9.8pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered tha...
CVE-2014-6274HIGH7.5git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey...
CVE-2014-0468CRITICAL9.8Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the use...
CVE-2014-5470CRITICAL9.8Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for pa...
CVE-2014-125111LOW3.5A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue i...
CVE-2014-125110LOW3.5A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected...
CVE-2014-125109MEDIUM6.1A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerab...
CVE-2014-125108MEDIUM6.1A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue aff...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now