2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-0619——Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code an...
CVE-2014-4766——IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading a...
CVE-2014-3829——displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot...
CVE-2014-3828——Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3...
CVE-2014-8764——DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass...
CVE-2014-8763——DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass auth...
CVE-2014-8762——The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a craf...
CVE-2014-8761——inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attack...
CVE-2014-8381——Multiple cross-site scripting (XSS) vulnerabilities in Megapolis.Portal Manager allow remote attackers to inject arbitra...
CVE-2014-8325——The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denia...
CVE-2014-8088——The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3....
CVE-2014-7968——VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.
CVE-2014-7183——Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attac...
CVE-2014-7182——Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remot...
CVE-2014-6387——gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will ...
CVE-2014-3677——Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers...
CVE-2014-3676——Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related...
CVE-2014-3675——Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
CVE-2014-4450——The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields wit...
CVE-2014-4449——iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-...
CVE-2014-4448——House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physic...
CVE-2014-3111——Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject ...
CVE-2014-2531——SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx...
CVE-2014-8380——Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML ...
CVE-2014-8379——Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote auth...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now