2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-2023Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo...
CVE-2014-0691Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote atta...
CVE-2014-3744Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary fi...
CVE-2014-3741The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attack...
CVE-2014-8491The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a requ...
CVE-2014-7813Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource c...
CVE-2014-7242The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission a...
CVE-2014-3709The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote at...
CVE-2014-3706ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to ver...
CVE-2014-3531Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject a...
CVE-2014-3164cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers...
CVE-2014-9118The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm...
CVE-2014-8357backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a ...
CVE-2014-2664Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/Profi...
CVE-2014-9733nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified ...
CVE-2014-9697Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote attackers to cause a memory leak or denial of service (m...
CVE-2014-9678FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile...
CVE-2014-9677Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inj...
CVE-2014-9489The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib befor...
CVE-2014-9487The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary fil...
CVE-2014-8324network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via...
CVE-2014-8323buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) vi...
CVE-2014-0208Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remo...
CVE-2014-9148Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update"...
CVE-2014-9147Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup fil...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now