2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-10069——Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which ...
CVE-2014-8579——TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account,...
CVE-2014-8540——The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitra...
CVE-2014-8336——The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attacke...
CVE-2014-8335——(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for Word...
CVE-2014-7862——The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at...
CVE-2014-8119——The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash...
CVE-2014-4978——The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary file...
CVE-2014-3630——XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2...
CVE-2014-0121——The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary comman...
CVE-2014-0120——Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the a...
CVE-2014-3651——JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a larg...
CVE-2014-4914——The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re...
CVE-2014-8389——cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21....
CVE-2014-8358——Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)...
CVE-2014-3250——The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m...
CVE-2014-3150——Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, ...
CVE-2014-0219——Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial...
CVE-2014-4000——Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c...
CVE-2014-0073——The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befor...
CVE-2014-0072——ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0....
CVE-2014-0115——Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary fi...
CVE-2014-3624——Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to ...
CVE-2014-3600——XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified...
CVE-2014-3579——XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspe...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now