2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9211 | MEDIUM | 6.1 | 0.9% | Jan 14, 2020 | ClickDesk version 4.3 and below has persistent cross site scripting |
| CVE-2014-9382 | MEDIUM | 6.5 | 0.8% | Jan 13, 2020 | Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation |
| CVE-2014-6059 | HIGH | 7.2 | 3.3% | Jan 13, 2020 | WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability |
| CVE-2014-6039 | HIGH | 7.5 | 68.8% | Jan 13, 2020 | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio... |
| CVE-2014-6038 | HIGH | 7.5 | 72.8% | Jan 13, 2020 | Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili... |
| CVE-2014-5381 | CRITICAL | 9.8 | 7.1% | Jan 13, 2020 | Grand MA 300 allows a brute-force attack on the PIN. |
| CVE-2014-5380 | HIGH | 7.5 | 4.3% | Jan 13, 2020 | Grand MA 300 allows retrieval of the access PIN from sniffed data. |
| CVE-2014-5093 | CRITICAL | 9.8 | 3.8% | Jan 10, 2020 | Status2k does not remove the install directory allowing credential reset. |
| CVE-2014-5092 | HIGH | 8.8 | 7.1% | Jan 10, 2020 | Status2k allows Remote Command Execution in admin/options/editpl.php. |
| CVE-2014-4561 | MEDIUM | 6.1 | 3.7% | Jan 10, 2020 | The ultimate-weather plugin 1.0 for WordPress has XSS |
| CVE-2014-5081 | CRITICAL | 9.8 | 10.5% | Jan 10, 2020 | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass |
| CVE-2014-4984 | CRITICAL | 9.8 | 3.0% | Jan 10, 2020 | Déjà Vu Crescendo Sales CRM has remote SQL Injection |
| CVE-2014-4982 | CRITICAL | 9.8 | 4.6% | Jan 10, 2020 | LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server. |
| CVE-2014-4530 | MEDIUM | 6.1 | 0.9% | Jan 10, 2020 | flog plugin 0.1 for WordPress has XSS |
| CVE-2014-5013 | HIGH | 8.8 | 4.6% | Jan 10, 2020 | DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383. |
| CVE-2014-5012 | MEDIUM | 6.5 | 1.3% | Jan 10, 2020 | DOMPDF before 0.6.2 allows denial of service. |
| CVE-2014-5011 | MEDIUM | 6.5 | 1.6% | Jan 10, 2020 | DOMPDF before 0.6.2 allows Information Disclosure. |
| CVE-2014-3753 | MEDIUM | 5.5 | 0.9% | Jan 9, 2020 | AgileBits 1Password through 1.0.9.340 allows security feature bypass |
| CVE-2014-3449 | CRITICAL | 9.8 | 2.7% | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability |
| CVE-2014-3448 | CRITICAL | 9.8 | 4.0% | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload |
| CVE-2014-3447 | HIGH | 7.5 | 1.8% | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability |
| CVE-2014-3211 | HIGH | 7.5 | 1.1% | Jan 9, 2020 | Publify before 8.0.1 is vulnerable to a Denial of Service attack |
| CVE-2014-2686 | HIGH | 7.5 | 1.2% | Jan 9, 2020 | Ansible prior to 1.5.4 mishandles the evaluation of some strings. |
| CVE-2014-2651 | CRITICAL | 9.8 | 1.7% | Jan 9, 2020 | Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Wo... |
| CVE-2014-2650 | CRITICAL | 9.8 | 2.6% | Jan 9, 2020 | Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web bas... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now