2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-5287HIGH8.8A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i...
CVE-2014-2072CRITICAL9.8Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
CVE-2014-1860CRITICAL9.8Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
CVE-2014-1409CRITICAL9.1MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due ...
CVE-2014-9908MEDIUM6.5A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to bloc...
CVE-2014-1598CRITICAL9.8centurystar 7.12 ActiveX Control has a Stack Buffer Overflow
CVE-2014-1454MEDIUM4.8Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user inp...
CVE-2014-5209MEDIUM5.3An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control me...
CVE-2014-8673CRITICAL9.8Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in...
CVE-2014-9405MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebo...
CVE-2014-8674MEDIUM5.4Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the doc...
CVE-2014-3743MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers...
CVE-2014-1850Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3743. Reason: This candidate is a duplicate of C...
CVE-2014-8516CRITICAL9.8Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co...
CVE-2014-8337CRITICAL9.8Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier ...
CVE-2014-5516MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0...
CVE-2014-5140HIGH8.8The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha...
CVE-2014-4196MEDIUM6.1Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attack...
CVE-2014-10398MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client ...
CVE-2014-8182HIGH7.5An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was con...
CVE-2014-6275MEDIUM5.9FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by d...
CVE-2014-3590MEDIUM6.5Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Th...
CVE-2014-0245MEDIUM5.9It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For ...
CVE-2014-0183MEDIUM6.1Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the syste...
CVE-2014-0169MEDIUM6.5In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the se...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now