2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4968HIGH8.8The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for...
CVE-2014-2595CRITICAL9.8Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm...
CVE-2014-0234CRITICAL9.8The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a M...
CVE-2014-3827MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenti...
CVE-2014-3826MEDIUM5.4Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web...
CVE-2014-9753CRITICAL9.8confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing us...
CVE-2014-7969Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8739. Reason: This candidate is a duplicate of C...
CVE-2014-9748HIGH8.1The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent t...
CVE-2014-6447HIGH7.1Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues ...
CVE-2014-2052CRITICAL9.8Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitra...
CVE-2014-8347HIGH7.8An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a...
CVE-2014-5086HIGH8.8A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite...
CVE-2014-5085HIGH8.8A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, whi...
CVE-2014-5084HIGH8.8A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let ...
CVE-2014-5083HIGH8.8A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php,...
CVE-2014-8739CRITICAL9.8Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery...
CVE-2014-9470MEDIUM6.1Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork C...
CVE-2014-9127MEDIUM6.5Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote aut...
CVE-2014-9126MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to injec...
CVE-2014-7863HIGH7.5The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O...
CVE-2014-2225HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remo...
CVE-2014-5278MEDIUM5.3A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.
CVE-2014-5091CRITICAL9.8A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, wh...
CVE-2014-5087CRITICAL9.8A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could l...
CVE-2014-5468HIGH8.8A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now