2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9211MEDIUM6.1ClickDesk version 4.3 and below has persistent cross site scripting
CVE-2014-9382MEDIUM6.5Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
CVE-2014-6059HIGH7.2WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
CVE-2014-6039HIGH7.5ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio...
CVE-2014-6038HIGH7.5Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili...
CVE-2014-5381CRITICAL9.8Grand MA 300 allows a brute-force attack on the PIN.
CVE-2014-5380HIGH7.5Grand MA 300 allows retrieval of the access PIN from sniffed data.
CVE-2014-5093CRITICAL9.8Status2k does not remove the install directory allowing credential reset.
CVE-2014-5092HIGH8.8Status2k allows Remote Command Execution in admin/options/editpl.php.
CVE-2014-4561MEDIUM6.1The ultimate-weather plugin 1.0 for WordPress has XSS
CVE-2014-5081CRITICAL9.8sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
CVE-2014-4984CRITICAL9.8Déjà Vu Crescendo Sales CRM has remote SQL Injection
CVE-2014-4982CRITICAL9.8LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.
CVE-2014-4530MEDIUM6.1flog plugin 0.1 for WordPress has XSS
CVE-2014-5013HIGH8.8DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
CVE-2014-5012MEDIUM6.5DOMPDF before 0.6.2 allows denial of service.
CVE-2014-5011MEDIUM6.5DOMPDF before 0.6.2 allows Information Disclosure.
CVE-2014-3753MEDIUM5.5AgileBits 1Password through 1.0.9.340 allows security feature bypass
CVE-2014-3449CRITICAL9.8BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
CVE-2014-3448CRITICAL9.8BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload
CVE-2014-3447HIGH7.5BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
CVE-2014-3211HIGH7.5Publify before 8.0.1 is vulnerable to a Denial of Service attack
CVE-2014-2686HIGH7.5Ansible prior to 1.5.4 mishandles the evaluation of some strings.
CVE-2014-2651CRITICAL9.8Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Wo...
CVE-2014-2650CRITICAL9.8Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web bas...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now