2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-10069 | — | — | 4.0% | Jan 7, 2018 | Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which ... |
| CVE-2014-8579 | — | — | 2.0% | Jan 5, 2018 | TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account,... |
| CVE-2014-8540 | — | — | 2.2% | Jan 5, 2018 | The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitra... |
| CVE-2014-8336 | — | — | 2.6% | Jan 5, 2018 | The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attacke... |
| CVE-2014-8335 | — | — | 0.5% | Jan 5, 2018 | (1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for Word... |
| CVE-2014-7862 | — | — | 81.0% | Jan 4, 2018 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at... |
| CVE-2014-8119 | — | — | 2.7% | Dec 29, 2017 | The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash... |
| CVE-2014-4978 | — | — | 0.4% | Dec 29, 2017 | The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary file... |
| CVE-2014-3630 | — | — | 2.8% | Dec 29, 2017 | XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2... |
| CVE-2014-0121 | — | — | 3.9% | Dec 29, 2017 | The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary comman... |
| CVE-2014-0120 | — | — | 1.2% | Dec 29, 2017 | Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the a... |
| CVE-2014-3651 | — | — | 1.6% | Dec 29, 2017 | JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a larg... |
| CVE-2014-4914 | — | — | 2.3% | Dec 29, 2017 | The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re... |
| CVE-2014-8389 | — | — | 50.5% | Dec 28, 2017 | cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.... |
| CVE-2014-8358 | — | — | 5.0% | Dec 11, 2017 | Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)... |
| CVE-2014-3250 | — | — | 0.9% | Dec 11, 2017 | The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m... |
| CVE-2014-3150 | — | — | 1.9% | Nov 15, 2017 | Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, ... |
| CVE-2014-0219 | — | — | 0.7% | Nov 15, 2017 | Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial... |
| CVE-2014-4000 | — | — | 1.7% | Nov 15, 2017 | Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c... |
| CVE-2014-0073 | — | — | 8.1% | Oct 30, 2017 | The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befor... |
| CVE-2014-0072 | — | — | 7.7% | Oct 30, 2017 | ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.... |
| CVE-2014-0115 | — | — | 5.3% | Oct 30, 2017 | Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary fi... |
| CVE-2014-3624 | — | — | 3.8% | Oct 30, 2017 | Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to ... |
| CVE-2014-3600 | — | — | 9.9% | Oct 27, 2017 | XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified... |
| CVE-2014-3579 | — | — | 4.6% | Oct 27, 2017 | XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspe... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now