2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3409The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13...
CVE-2014-8760ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to ...
CVE-2014-7180Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and...
CVE-2014-6251Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a ...
CVE-2014-6230WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the ...
CVE-2014-3604Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domai...
CVE-2014-2021Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a...
CVE-2014-8346The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a net...
CVE-2014-7298adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX ...
CVE-2014-8073Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the ...
CVE-2014-8072The administration module in OpenMRS 2.1 Standalone Edition allows remote authenticated users to obtain read access via ...
CVE-2014-8071Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject a...
CVE-2014-7292Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.1612...
CVE-2014-7281Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a...
CVE-2014-2230Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to...
CVE-2014-0619Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code an...
CVE-2014-4766IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading a...
CVE-2014-3829displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot...
CVE-2014-3828Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3...
CVE-2014-8764DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass...
CVE-2014-8763DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass auth...
CVE-2014-8762The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a craf...
CVE-2014-8761inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attack...
CVE-2014-8381Multiple cross-site scripting (XSS) vulnerabilities in Megapolis.Portal Manager allow remote attackers to inject arbitra...
CVE-2014-8325The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denia...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now