2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9002 | — | — | 5.1% | Nov 20, 2014 | Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary com... |
| CVE-2014-9001 | — | — | 2.8% | Nov 20, 2014 | reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via s... |
| CVE-2014-9000 | — | — | 8.9% | Nov 20, 2014 | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows ... |
| CVE-2014-8999 | — | — | 1.7% | Nov 20, 2014 | SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated u... |
| CVE-2014-8998 | — | — | 36.8% | Nov 20, 2014 | lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c... |
| CVE-2014-8997 | — | — | 9.1% | Nov 20, 2014 | Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al... |
| CVE-2014-8996 | — | — | 1.9% | Nov 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Nibbleblog before 4.0.2 allow remote attackers to inject arbitrar... |
| CVE-2014-8995 | — | — | 2.2% | Nov 20, 2014 | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the Us... |
| CVE-2014-8387 | — | — | 23.8% | Nov 20, 2014 | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar... |
| CVE-2014-2382 | — | — | 0.6% | Nov 20, 2014 | The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to ... |
| CVE-2014-8595 | — | — | 0.4% | Nov 19, 2014 | arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM... |
| CVE-2014-8594 | — | — | 2.2% | Nov 19, 2014 | The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page ... |
| CVE-2014-7828 | — | — | 1.8% | Nov 19, 2014 | FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password r... |
| CVE-2014-6627 | — | — | 1.9% | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via u... |
| CVE-2014-6626 | — | — | 2.3% | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administra... |
| CVE-2014-6625 | — | — | 1.5% | Nov 19, 2014 | The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to ... |
| CVE-2014-6624 | — | — | 1.3% | Nov 19, 2014 | The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to ... |
| CVE-2014-6622 | — | — | 1.2% | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filena... |
| CVE-2014-6621 | — | — | 1.2% | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page i... |
| CVE-2014-5342 | — | — | 2.7% | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via u... |
| CVE-2014-8629 | — | — | 1.9% | Nov 19, 2014 | Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remo... |
| CVE-2014-7290 | — | — | 1.9% | Nov 19, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Atlas Systems Aeon 3.5 and 3.6 allow remote attackers to inject a... |
| CVE-2014-7910 | — | — | 7.9% | Nov 19, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o... |
| CVE-2014-7909 | — | — | 1.6% | Nov 19, 2014 | effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitiali... |
| CVE-2014-7908 | — | — | 1.6% | Nov 19, 2014 | Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.6... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now