2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-10069Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which ...
CVE-2014-8579TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account,...
CVE-2014-8540The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitra...
CVE-2014-8336The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attacke...
CVE-2014-8335(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for Word...
CVE-2014-7862The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at...
CVE-2014-8119The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash...
CVE-2014-4978The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary file...
CVE-2014-3630XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2...
CVE-2014-0121The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary comman...
CVE-2014-0120Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the a...
CVE-2014-3651JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a larg...
CVE-2014-4914The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re...
CVE-2014-8389cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21....
CVE-2014-8358Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)...
CVE-2014-3250The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m...
CVE-2014-3150Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, ...
CVE-2014-0219Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial...
CVE-2014-4000Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c...
CVE-2014-0073The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befor...
CVE-2014-0072ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0....
CVE-2014-0115Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary fi...
CVE-2014-3624Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to ...
CVE-2014-3600XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified...
CVE-2014-3579XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspe...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now