2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2023 | — | — | 4.1% | Oct 26, 2017 | Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo... |
| CVE-2014-0691 | — | — | 1.0% | Oct 24, 2017 | Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote atta... |
| CVE-2014-3744 | — | — | 34.0% | Oct 23, 2017 | Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary fi... |
| CVE-2014-3741 | — | — | 3.8% | Oct 23, 2017 | The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attack... |
| CVE-2014-8491 | — | — | 1.9% | Oct 18, 2017 | The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a requ... |
| CVE-2014-7813 | — | — | 1.0% | Oct 18, 2017 | Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource c... |
| CVE-2014-7242 | — | — | 0.6% | Oct 18, 2017 | The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission a... |
| CVE-2014-3709 | — | — | 0.8% | Oct 18, 2017 | The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote at... |
| CVE-2014-3706 | — | — | 0.7% | Oct 18, 2017 | ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to ver... |
| CVE-2014-3531 | — | — | 1.2% | Oct 18, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject a... |
| CVE-2014-3164 | — | — | 1.0% | Oct 18, 2017 | cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers... |
| CVE-2014-9118 | — | — | 53.4% | Oct 17, 2017 | The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm... |
| CVE-2014-8357 | — | — | 5.4% | Oct 17, 2017 | backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a ... |
| CVE-2014-2664 | — | — | 2.9% | Oct 17, 2017 | Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/Profi... |
| CVE-2014-9733 | — | — | 1.4% | Oct 17, 2017 | nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified ... |
| CVE-2014-9697 | — | — | 0.8% | Oct 17, 2017 | Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote attackers to cause a memory leak or denial of service (m... |
| CVE-2014-9678 | — | — | 1.0% | Oct 17, 2017 | FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile... |
| CVE-2014-9677 | — | — | 1.2% | Oct 17, 2017 | Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inj... |
| CVE-2014-9489 | — | — | 2.3% | Oct 17, 2017 | The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib befor... |
| CVE-2014-9487 | — | — | 2.0% | Oct 17, 2017 | The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary fil... |
| CVE-2014-8324 | — | — | 4.2% | Oct 17, 2017 | network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via... |
| CVE-2014-8323 | — | — | 3.3% | Oct 17, 2017 | buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) vi... |
| CVE-2014-0208 | — | — | 0.8% | Oct 16, 2017 | Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remo... |
| CVE-2014-9148 | — | — | 11.4% | Oct 16, 2017 | Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update"... |
| CVE-2014-9147 | — | — | 11.4% | Oct 16, 2017 | Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup fil... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now