2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4968 | HIGH | 8.8 | 6.1% | Feb 12, 2020 | The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for... |
| CVE-2014-2595 | CRITICAL | 9.8 | 16.5% | Feb 12, 2020 | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm... |
| CVE-2014-0234 | CRITICAL | 9.8 | 3.7% | Feb 12, 2020 | The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a M... |
| CVE-2014-3827 | MEDIUM | 5.4 | 0.6% | Feb 11, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenti... |
| CVE-2014-3826 | MEDIUM | 5.4 | 0.6% | Feb 11, 2020 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web... |
| CVE-2014-9753 | CRITICAL | 9.8 | 2.9% | Feb 11, 2020 | confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing us... |
| CVE-2014-7969 | — | — | — | Feb 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8739. Reason: This candidate is a duplicate of C... |
| CVE-2014-9748 | HIGH | 8.1 | 2.5% | Feb 11, 2020 | The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent t... |
| CVE-2014-6447 | HIGH | 7.1 | 0.8% | Feb 11, 2020 | Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues ... |
| CVE-2014-2052 | CRITICAL | 9.8 | 2.5% | Feb 11, 2020 | Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitra... |
| CVE-2014-8347 | HIGH | 7.8 | 1.4% | Feb 11, 2020 | An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a... |
| CVE-2014-5086 | HIGH | 8.8 | 9.8% | Feb 10, 2020 | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite... |
| CVE-2014-5085 | HIGH | 8.8 | 5.8% | Feb 10, 2020 | A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, whi... |
| CVE-2014-5084 | HIGH | 8.8 | 7.7% | Feb 10, 2020 | A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let ... |
| CVE-2014-5083 | HIGH | 8.8 | 5.8% | Feb 10, 2020 | A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php,... |
| CVE-2014-8739 | CRITICAL | 9.8 | 91.7% | Feb 8, 2020 | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery... |
| CVE-2014-9470 | MEDIUM | 6.1 | 1.4% | Feb 8, 2020 | Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork C... |
| CVE-2014-9127 | MEDIUM | 6.5 | 1.4% | Feb 8, 2020 | Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote aut... |
| CVE-2014-9126 | MEDIUM | 6.1 | 1.1% | Feb 8, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to injec... |
| CVE-2014-7863 | HIGH | 7.5 | 83.4% | Feb 8, 2020 | The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O... |
| CVE-2014-2225 | HIGH | 8.8 | 1.3% | Feb 8, 2020 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remo... |
| CVE-2014-5278 | MEDIUM | 5.3 | 1.5% | Feb 7, 2020 | A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs. |
| CVE-2014-5091 | CRITICAL | 9.8 | 15.2% | Feb 7, 2020 | A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, wh... |
| CVE-2014-5087 | CRITICAL | 9.8 | 7.2% | Feb 7, 2020 | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could l... |
| CVE-2014-5468 | HIGH | 8.8 | 52.6% | Feb 7, 2020 | A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now