2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7871 | — | — | 1.6% | Nov 21, 2014 | SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote ... |
| CVE-2014-7137 | — | — | 1.7% | Nov 21, 2014 | Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbi... |
| CVE-2014-5395 | — | — | 0.9% | Nov 21, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S... |
| CVE-2014-8388 | — | — | 1.1% | Nov 21, 2014 | Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to e... |
| CVE-2014-8000 | — | — | 2.3% | Nov 21, 2014 | Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL request... |
| CVE-2014-7195 | — | — | 0.9% | Nov 21, 2014 | Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment K... |
| CVE-2014-7194 | — | — | 1.1% | Nov 21, 2014 | TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot b... |
| CVE-2014-9027 | — | — | 0.9% | Nov 20, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the auth... |
| CVE-2014-9026 | — | — | 0.9% | Nov 20, 2014 | The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which a... |
| CVE-2014-9025 | — | — | 1.2% | Nov 20, 2014 | The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 ... |
| CVE-2014-9024 | — | — | 1.3% | Nov 20, 2014 | The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection v... |
| CVE-2014-9023 | — | — | 1.0% | Nov 20, 2014 | The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages... |
| CVE-2014-9022 | — | — | 1.5% | Nov 20, 2014 | The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers ... |
| CVE-2014-9021 | — | — | 1.9% | Nov 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web scri... |
| CVE-2014-9020 | — | — | 2.1% | Nov 20, 2014 | Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote ... |
| CVE-2014-9019 | — | — | 1.0% | Nov 20, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the auth... |
| CVE-2014-8769 | — | — | 5.5% | Nov 20, 2014 | tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of ... |
| CVE-2014-8768 | — | — | 20.4% | Nov 20, 2014 | Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow rem... |
| CVE-2014-8767 | — | — | 5.5% | Nov 20, 2014 | Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attacke... |
| CVE-2014-8493 | — | — | 8.1% | Nov 20, 2014 | ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque... |
| CVE-2014-3625 | — | — | 10.1% | Nov 20, 2014 | Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and... |
| CVE-2014-9006 | — | — | 1.6% | Nov 20, 2014 | Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attack... |
| CVE-2014-9005 | — | — | 1.2% | Nov 20, 2014 | Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL comm... |
| CVE-2014-9004 | — | — | 1.5% | Nov 20, 2014 | Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-9003 | — | — | 1.1% | Nov 20, 2014 | Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authenti... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now